Port Acls - Cisco 3020 - Catalyst Blade Switch Configuration Manual

Cisco catalyst blade switch 3020 for hp software configuration guide, rel. 12.2(25)sef1
Hide thumbs Also See for 3020 - Cisco Catalyst Blade Switch:
Table of Contents

Advertisement

Chapter 26
Configuring Network Security with ACLs

Port ACLs

Port ACLs are ACLs that are applied to Layer 2 interfaces on a switch. Port ACLs are supported only on
physical interfaces and not on EtherChannel interfaces and can be applied only on interfaces in the
inbound direction. These access lists are supported:
The switch examines ACLs associated with all inbound features configured on a given interface and
permits or denies packet forwarding based on how the packet matches the entries in the ACL. In this way,
ACLs control access to a network or to part of a network.
to control access to a network when all servers are in the same VLAN. ACLs applied at the Layer 2 input
would allow Blade Server A to access the Human Resources network, but prevent Blade Server B from
accessing the same network. Port ACLs can only be applied to Layer 2 interfaces in the inbound
direction.
Figure 26-1
When you apply a port ACL to a trunk port, the ACL filters traffic on all VLANs present on the trunk
port. When you apply a port ACL to a port with voice VLAN, the ACL filters traffic on both data and
voice VLANs.
With port ACLs, you can filter IP traffic by using IP access lists and non-IP traffic by using MAC
addresses. You can filter both IP and non-IP traffic on the same Layer 2 interface by applying both an IP
access list and a MAC access list to the interface.
OL-8915-01
Standard IP access lists using source addresses
Extended IP access lists using source and destination addresses and optional protocol type
information
MAC extended access lists using source and destination MAC addresses and optional protocol type
information
Using ACLs to Control Traffic to a Network
Human
Resources
network
= ACL denying traffic from
and permitting traffic from
= Packet
Figure 26-1
Blade Server
A
Blade Server
B
Research &
Development
network
Blade Server
B
Blade Server
A
Cisco Catalyst Blade Switch 3020 for HP Software Configuration Guide
Understanding ACLs
is an example of using port ACLs
26-3

Advertisement

Table of Contents
loading

Table of Contents