Cisco WS-C6506 Software Manual page 416

Catalyst 6500 series switch
Hide thumbs Also See for WS-C6506:
Table of Contents

Advertisement

Using VACLs with Cisco IOS ACLs
Example 1
This example shows that the VACL does not follow the recommended guidelines (in line 9, a deny action
is defined instead of using the implicit deny action at the end of the ACL), and the resultant merge
increases the number of ACEs:
******** VACL
1
permit udp host 194.72.72.33 194.72.6.160 0.0.0.15
2
permit udp host 147.150.213.94 194.72.6.64 0.0.0.15 eq bootps
3
permit udp 194.73.74.0 0.0.0.255 host 194.72.6.205 eq syslog
4
permit udp host 167.221.23.1 host 194.72.6.198 eq tacacs
5
permit udp 194.72.136.1 0.0.3.128 194.72.6.64 0.0.0.15 eq tftp
6
permit udp host 193.6.65.17 host 194.72.6.205 gt 1023
7
permit tcp any host 194.72.6.52
8
permit tcp any host 194.72.6.52 eq 113
9
deny tcp any host 194.72.6.51 eq ftp
10 permit tcp any host 194.72.6.51 eq ftp-data
11 permit tcp any host 194.72.6.51
12 permit tcp any eq domain host 194.72.6.51
13 permit tcp any host 194.72.6.51 gt 1023
14 permit ip
******** Cisco IOS ACL ************
1
deny ip any host 239.255.255.255
2
permit ip any any
******** MERGE **********
has 91 entries entries
Example 2
In
Example
of the ACL) and modify lines 11 and 12 (lines 11 and 12 are modified so that the traffic that line 9 would
have dropped is not permitted), you see the following equivalent ACL with improved merge results:
********
1
permit udp host 194.72.72.33 194.72.6.160 0.0.0.15
2
permit udp host 147.150.213.94 194.72.6.64 0.0.0.15 eq bootps
3
permit udp 194.73.74.0 0.0.0.255 host 194.72.6.205 eq syslog
4
permit udp host 167.221.23.1 host 194.72.6.198 eq tacacs
5
permit udp 194.72.136.1 0.0.3.128 194.72.6.64 0.0.0.15 eq tftp
6
permit udp host 193.6.65.17 host 194.72.6.205 gt 1023
7
permit tcp any host 194.72.6.52
8
permit tcp any host 194.72.6.52 eq 113
9
permit tcp any host 194.72.6.51 eq ftp-data
10 permit tcp any host 194.72.6.51 neq ftp
11 permit tcp any eq domain host 194.72.6.51 neq ftp
12 permit tcp any host 194.72.6.51 gt 1023
13 permit ip
******** Cisco IOS ACL ************
1
deny ip any host 239.255.255.255
2
permit ip any any
******** MERGE ***********
has 78 entries
Example 3
This example shows that the VACL does not follow the recommended guidelines (all the action types are
not grouped), and the resultant merge significantly increases the number of ACEs:
******** VACL
1
deny ip 0.0.0.0 255.255.255.0 any
2
deny ip 0.0.0.255 255.255.255.0 any
3
deny ip any 0.0.0.0 255.255.255.0
4
permit ip any host 239.255.255.255
5
permit ip any host 255.255.255.255
Catalyst 6500 Series Switch Software Configuration Guide—Release 8.7
15-20
***********
any host 1.1.1.1
1, if you follow the guidelines and remove line 9 (the implicit deny is then used at the end
**********
VACL
any host 1.1.1.1
***********
Chapter 15
Configuring Access Control
OL-8978-04

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Catalyst 6506Catalyst 6509Catalyst 6513

Table of Contents