C H A P T E R 1 Configuring Security Access Control Lists; Acl Overview - Cisco 4700M Configuration Manual

Application control engine appliance security
Hide thumbs Also See for 4700M:
Table of Contents

Advertisement

ACL Overview

ACL Overview
Cisco 4700 Series Application Control Engine Appliance Security Configuration Guide
1-2
An ACL consists of a series of statements called ACL entries that define the
network traffic profile. Each entry permits or denies network traffic (inbound and
outbound) to the parts of your network specified in the entry. Each entry also
contains a filter element that is based on criteria such as the source address, the
destination address, the protocol, and protocol-specific parameters such as ports
and so on.
An implicit deny-all entry exists at the end of each ACL, so you must configure
an ACL on each interface that you want to permit connections. Otherwise, the
ACE denies all traffic on the interface.
ACLs allow you to control network connection setups rather than processing each
packet. Such ACLs are commonly referred to as security ACLs.
You can configure ACLs as parts of other features (for example, security, Network
Address Translation (NAT), server load balancing (SLB), and so on). The ACE
merges these individual ACLs into one large ACL called a merged ACL. The ACL
compiler then parses the merged ACL and generates the ACL lookup mechanisms.
A match on this merged ACL can result in multiple actions.
For example, one use of ACLs could be to permit all e-mail traffic on a VLAN,
but block Telnet traffic. You can also use ACLs to allow one client to access a part
of the network and prevent another client from accessing that same area.
When configuring ACLs, you must apply an ACL to an interface to control traffic
on that interface. Applying an ACL on an interface assigns the ACL and its entries
to that interface.
You can apply only one extended ACL to each direction (inbound or outbound) of
an interface. You can also apply the same ACL on multiple interfaces.You can
apply EtherType ACLs only in the inbound direction and only on Layer 2
interfaces.
This section contains the following topics:
ACL Types and Uses
ACL Guidelines
Chapter 1
Configuring Security Access Control Lists
OL-16202-01

Advertisement

Table of Contents
loading

This manual is also suitable for:

4700 series

Table of Contents