VLAN Maps
136
G8264 Application Guide for ENOS 8.4
A VLAN map (VMap) is an ACL that can be assigned to a VLAN or VM group
rather than to a switch port as with IPv4 ACLs. This is particularly useful in a
virtualized environment where traffic filtering and metering policies must follow
virtual machines (VMs) as they migrate between hypervisors.
Note: VLAN maps for VM groups are not supported simultaneously on the same
ports as vNICs (see Chapter
The G8264 supports up to 128 VMaps.
Individual VMap filters are configured in the same fashion as IPv4 ACLs, except
that VLANs cannot be specified as a filtering criteria (unnecessary, since the VMap
are assigned to a specific VLAN or associated with a VM group VLAN).
VMaps are configured using the following ISCLI configuration command path:
RS G8264(config)# accesscontrol vmap <VMap ID> ?
action Set filter action
egressport Set to filter for packets egressing this port
ethernet Ethernet header options
ipv4 IP version 4 header options
meter ACL metering configuration
mirror Mirror options
packetformat Set to filter specific packet format types
remark ACL remark configuration
statistics Enable access control list statistics
tcpudp TCP and UDP filtering options
Once a VMap filter is created, it can be assigned or removed using the following
configuration commands:
For regular VLAN, use config‐vlan mode:
RS G8264(config)# vlan <VLAN ID>
RS G8264(configvlan)# [no] vmap <VMap ID> [serverports|
nonserverports]
For a VM group (see "VM Group Types" on page
configuration mode:
RS G8264(config)# [no] virt vmgroup <ID> vmap <VMap ID>
[serverports|nonserverports]
Note: Each VMap can be assigned to only one VLAN or VM group. However, each
VLAN or VM group may have multiple VMaps assigned to it.
When the optional serverports or nonserverports parameter is specified,
the action to add or remove the VMap is applied for either the switch server ports
(serverports) or uplink ports (nonserverports). If omitted, the operation
will be applied to all ports in the associated VLAN or VM group.
19, "Virtual NICs").
342), use the global