R
R
ReD2017-03-30 10:45:21
Cisco
ReD, 2017-03-30 10:45:21

When when on Cisco to apply an ACL on the ingress and when on the egress of an interface?

Hello!
I just can’t catch a clear difference between
ip access-group in
and
ip access-group out
Please help me understand the principle by which it would be possible to immediately determine in which cases ACL should be hung on the output (out), and when on the input (in) of the interface?

Answer the question

In order to leave comments, you need to log in

2 answer(s)
C
cssman, 2017-03-30
@cssman

on in any incoming connections (what came to your network), on out - outgoing (what will leave your network).

I
Ilya, 2017-04-18
@aforism

To determine where to hang the access list, there is a rule - you should always look relative to the device in for traffic that enters the device, out for outgoing from the device.

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question