Cisco ACL deny icmp

400 pts.
Tags:
Cisco 4506
Cisco Catalyst
Cisco switches
ICMP
VLAN
I have three cisco core 4506 and working with 20 different vlans. i am trying to create deny icmp for vlan 67 subnet 192.168.40.0 255.255.255.224. i tried in many way but i am fail. any host can ping to this subnet and this subnet can ping to any host. but i want to deny for both.

 



Software/Hardware used:
cisco catalyst 4506 switches

Answer Wiki

Thanks. We'll let you know when a new response is added.

You need to implement this on the switch that has the VLAN67 interface, which is also the default-gateway for the subnet. If you have this running HSRP or VRRP, then implement it on all the switches with a VLAN67 interface.

Try the following which only denies PING, but allows other ICMP messages. If you want to deny all ICMP then leave out the second line, and remove the ‘echo’ from the first line. Change the number from ’100′ if you already have an access list with this number.
<b>
access-list 100 deny icmp any any echo
access-list 100 deny icmp any any echo-reply
access-list 100 permit ip any any</b>

On the Interface VLAN67
<b>
ip access-group 100 in
ip access-group 100 out</b>

Hope this helps.

Discuss This Question:  

 
There was an error processing your information. Please try again later.
Thanks. We'll let you know when a new response is added.
Send me notifications when members answer or reply to this question.

REGISTER or login:

Forgot Password?
By submitting you agree to receive email from TechTarget and its partners. If you reside outside of the United States, you consent to having your personal data transferred to and processed in the United States. Privacy

Forgot Password

No problem! Submit your e-mail address below. We'll send you an e-mail containing your password.

Your password has been sent to:

To follow this tag...

There was an error processing your information. Please try again later.

REGISTER or login:

Forgot Password?
By submitting you agree to receive email from TechTarget and its partners. If you reside outside of the United States, you consent to having your personal data transferred to and processed in the United States. Privacy

Thanks! We'll email you when relevant content is added and updated.

Following