Cisco 4500M Software Manual page 497

Software guide
Table of Contents

Advertisement

Chapter 35
Configuring Network Security with ACLs
Example 2
In this example, the VLAN map is configured to drop IP packets and to forward MAC packets by default.
By applying standard ACL 101 and the extended named access lists igmp-match and tcp-match, the
VLAN map is configured to do the following:
Switch(config)# access-list 101 permit udp any any
Switch(config)# ip access-list extended igmp-match
Switch(config-ext-nacl)# permit igmp any any
Switch(config)# ip access-list extended tcp-match
Switch(config-ext-nacl)# permit tcp any any
Switch(config-ext-nacl)# exit
Switch(config)# vlan access-map drop-ip-default 10
Switch(config-access-map)# match ip address 101
Switch(config-access-map)# action forward
Switch(config-access-map)# exit
Switch(config)# vlan access-map drop-ip-default 20
Switch(config-access-map)# match ip address igmp-match
Switch(config-access-map)# action drop
Switch(config-access-map)# exit
Switch(config)# vlan access-map drop-ip-default 30
Switch(config-access-map)# match ip address tcp-match
Switch(config-access-map)# action forward
Example 3
In this example, the VLAN map is configured to drop MAC packets and forward IP packets by default.
By applying MAC extended access lists, good-hosts and good-protocols, the VLAN map is configured
to do the following:
Switch(config)# mac access-list extended good-hosts
Switch(config-ext-macl)# permit host 000.0c00.0111 any
Switch(config-ext-macl)# permit host 000.0c00.0211 any
Switch(config-ext-nacl)# exit
Switch(config)# mac access-list extended good-protocols
Switch(config-ext-macl)# permit any any protocol-family decnet
Switch(config-ext-macl)# permit any any protocol-family vines
Switch(config-ext-nacl)# exit
Switch(config)# vlan access-map drop-mac-default 10
Switch(config-access-map)# match mac address good-hosts
Switch(config-access-map)# action forward
Switch(config-access-map)# exit
Switch(config)# vlan access-map drop-mac-default 20
Switch(config-access-map)# match mac address good-protocols
Switch(config-access-map)# action forward
OL-6696-01
Forward all UDP packets
Drop all IGMP packets
Forward all TCP packets
Drop all other IP packets
Forward all non-IP packets
Forward MAC packets from hosts 0000.0c00.0111 and 0000.0c00.0211
Forward MAC packets of DECnet or VINES (Virtual Integrated Network Service) protocol-family
Drop all other non-IP packets
Forward all IP packets
Software Configuration Guide—Release 12.2(25)EW
Configuring VLAN Maps
35-15

Advertisement

Table of Contents
loading

This manual is also suitable for:

4500 series

Table of Contents