March 16th, 2020 Go to comments

The “deny tcp any host eq 80” command means “block all (any) traffic from accessing web server at on port 80”. And since it is applied to VLAN 20 interface so only computers on VLAN 20 are affected.

In summary, just notice that here is the destination IP address, not source address.

Note: The traffic flow from hosts in VLAN 20 to the Web Server is: host in VLAN 20 -> Interface VLAN 20 -> Interface VLAN 30 -> Web Server. If we place the ACL: host in VLAN 20 -> (ACL Inbound) Interface VLAN 20 -> Interface VLAN 30 -> Web Server. Therefore the ACL can block traffic from VLAN 20.

