SNR S2940-8G-v2 Switch Configuration Guide
VLAN-ACL Configuration
Switch(config)#ip access-list extended vacl_b
Switch(config-ip-ext-nacl-vacl_a)#permit ip any-source 192.168.1.0 0.0.0.255
Switch(config-ip-ext-nacl-vacl_a)#deny ip any-source any-destination
4) Apply the configuration to VLAN
Switch(config)#vacl ip access-group vacl_a in vlan 1
Switch(config)#vacl ip access-group vacl_b in vlan 2
56.4 VLAN-ACL Troubleshooting
• When VLAN ACL and Port ACL are configured at the same time, the principle of denying
firstly is used. When the packets match VLAN ACL and Port ACL at the same time, as long
as one rule is drop, then the final action is drop.
• Each ACL of different types can only apply one on a VLAN, such as the basic IP ACL, each
VLAN can applies one only.
369