Hide thumbs Also See for 6500 Series:
Table of Contents

Advertisement

Chapter 23
Configuring Network Security
When you configure a VACL and apply it to a VLAN, all packets entering the VLAN are checked against
this VACL. If you apply a VACL to the VLAN and an ACL to a routed interface in the VLAN, a packet
coming in to the VLAN is first checked against the VACL and, if permitted, is then checked against the
input ACL before it is handled by the routed interface. When the packet is routed to another VLAN, it
is first checked against the output ACL applied to the routed interface and, if permitted, the VACL
configured for the destination VLAN is applied. If a VACL is configured for a packet type and a packet
of that type does not match the VACL, the default action is deny.
Note

Bridged Packets

Figure 23-1
Figure 23-1 Applying VACLs on Bridged Packets
Host A
(VLAN 10)
78-14099-04
VACLs and CBAC cannot be configured on the same interface.
TCP Intercepts and Reflexive ACLs take precedence over a VACL action if these are configured on
the same interface.
IGMP packets are not checked against VACLs.
shows a VACL applied on bridged packets.
VACL
Bridged
Catalyst 6500 Series Switch
with PFC
Catalyst 6500 Series Switch Cisco IOS Software Configuration Guide—Release 12.1 E
VACL
Host B
(VLAN 10)
Configuring VLAN ACLs
23-9

Advertisement

Table of Contents
loading

Table of Contents