How To Configure Acls; Configuring Ipv4 Acls; Creating A Numbered Standard Acl - Cisco Catalyst 2960-XR Security Configuration Manual

Ios release 15.0 2 ex1
Hide thumbs Also See for Catalyst 2960-XR:
Table of Contents

Advertisement

How to Configure ACLs

For outbound ACLs, after receiving and routing a packet to a controlled interface, the switch checks the packet
against the ACL. If the ACL permits the packet, the switch sends the packet. If the ACL rejects the packet,
the switch discards the packet.
By default, the input interface sends ICMP Unreachable messages whenever a packet is discarded, regardless
of whether the packet was discarded because of an ACL on the input interface or because of an ACL on the
output interface. ICMP Unreachables are normally limited to no more than one every one-half second per
input interface, but this can be changed by using the ip icmp rate-limit unreachable global configuration
command.
When you apply an undefined ACL to an interface, the switch acts as if the ACL has not been applied to the
interface and permits all packets. Remember this behavior if you use undefined ACLs for network security.
Related Topics
Applying an IPv4 ACL to an Interface, on page 130
Restrictions for Configuring Network Security with ACLs, on page 105
How to Configure ACLs

Configuring IPv4 ACLs

These are the steps to use IP ACLs on the switch:
SUMMARY STEPS
1. Create an ACL by specifying an access list number or name and the access conditions.
2. Apply the ACL to interfaces or terminal lines. You can also apply standard and extended IP ACLs to
VLAN maps.
DETAILED STEPS
Command or Action
Step 1
Create an ACL by specifying an access list number or name and the access conditions.
Step 2
Apply the ACL to interfaces or terminal lines. You can also apply standard and extended
IP ACLs to VLAN maps.

Creating a Numbered Standard ACL

Beginning in privileged EXEC mode, follow these steps to create a numbered standard ACL:
Catalyst 2960-XR Switch Security Configuration Guide, Cisco IOS Release 15.0(2)EX1
120
Configuring IPv4 ACLs
Purpose
OL-29434-01

Advertisement

Table of Contents
loading

Table of Contents