Application Order; Rules; Source And Destination; Protocols - Cisco AP775A - Nexus Converged Network Switch 5010 Configuration Manual

Cli software configuration guide
Hide thumbs Also See for AP775A - Nexus Converged Network Switch 5010:
Table of Contents

Advertisement

Application Order

Table 28: Security ACL Applications
Application
Port ACL
VLAN ACL (VACL)
Application Order
When the switch processes a packet, it determines the forwarding path of the packet. The path determines
which ACLs that the switch applies to the traffic. The switch applies the Port ACLs first.

Rules

You can create rules in access-list configuration mode by using the permit or deny command. The switch
allows traffic that matches the criteria in a permit rule and blocks traffic that matches the criteria in a deny
rule. You have many options for configuring the criteria that traffic must meet in order to match the rule.

Source and Destination

In each rule, you specify the source and the destination of the traffic that matches the rule. You can specify
both the source and destination as a specific host, a network or group of hosts, or any host.

Protocols

ACLs allow you to identify traffic by protocol. For your convenience, you can specify some protocols by
name. For example, in an IPv4 ACL, you can specify ICMP by name.
You can specify any protocol by number. In IPv4 ACLs, you can specify protocols by the integer that represents
the Internet protocol number. For example, you can use 115 to specify Layer 2 Tunneling Protocol (L2TP)
traffic.

Implicit Rules

IP ACLs have implicit rules, which means that although these rules do not appear in the running configuration,
the switch applies them to traffic when no other rules in an ACL match.
Cisco Nexus 5000 Series Switch CLI Software Configuration Guide
280
Supported Interfaces
An ACL is considered a port ACL
when you apply it to one of the
following:
• Ethernet interface
• Ethernet port-channel
interface
When a port ACL is applied to a
trunk port, the ACL filters traffic
on all VLANs on the trunk port.
An ACL is a VACL when you use
an access map to associate the ACL
with an action, and then apply the
map to a VLAN.
Information About ACLs
Types of ACLs Supported
IPv4 ACLs
IPv6 ACLs
MAC ACLs
IPv4 ACLs
IPv6 ACLs
MAC ACLs
OL-16597-01

Advertisement

Table of Contents
loading

Table of Contents