Chapter 27 Configuring Network Security With Acls; Understanding Acls - Cisco WS-C3560-48PS-S Software Configuration Manual

Software configuration guide
Hide thumbs Also See for WS-C3560-48PS-S:
Table of Contents

Advertisement

Configuring Network Security with ACLs
This chapter describes how to configure network security on the Catalyst 3560 switch by using access
control lists (ACLs), which are also referred to in commands and tables as access lists.
Note
For complete syntax and usage information for the commands used in this chapter, refer to the command
reference for this release and the "Configuring IP Services" section of the Cisco IOS IP and IP Routing
Configuration Guide and the Cisco IOS IP and IP Routing Command Reference for IOS Release 12.1.
This chapter consists of these sections:

Understanding ACLs

Packet filtering can help limit network traffic and restrict network use by certain users or devices. ACLs
can filter traffic as it passes through a router or switch and permit or deny packets crossing specified
interfaces or VLANs. An ACL is a sequential collection of permit and deny conditions that apply to
packets. When a packet is received on an interface, the switch compares the fields in the packet against
any applied ACLs to verify that the packet has the required permissions to be forwarded, based on the
criteria specified in the access lists. It tests packets against the conditions in an access list one by one.
The first match determines whether the switch accepts or rejects the packets. Because the switch stops
testing conditions after the first match, the order of conditions in the list is critical. If no conditions
match, the switch rejects the packets. If there are no restrictions, the switch forwards the packet;
otherwise, the switch drops the packet. The switch can access-control all packets it switches, including
packets bridged within a VLAN.
78-16156-01
Understanding ACLs, page 27-1
Configuring IP ACLs, page 27-6
Creating Named MAC Extended ACLs, page 27-26
Configuring VLAN Maps, page 27-29
Using VLAN Maps with Router ACLs, page 27-36
Displaying ACL Configuration, page 27-40
C H A P T E R
Catalyst 3560 Switch Software Configuration Guide
27
27-1

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents