Acls And Multicast Packets; Displaying Ipv4 Acl Configuration - Cisco Catalyst 3750-X Software Configuration Manual

Hide thumbs Also See for Catalyst 3750-X:
Table of Contents

Advertisement

Chapter 37
Configuring Network Security with ACLs

ACLs and Multicast Packets

Figure 37-9
packet being routed has two different kinds of filters applied: one for destinations that are other ports in
the input VLAN and another for each of the destinations that are in other VLANs to which the packet
has been routed. The packet might be routed to more than one output VLAN, in which case a different
router output ACL and VLAN map would apply for each destination VLAN.
The final result is that the packet might be permitted in some of the output VLANs and not in others. A
copy of the packet is forwarded to those destinations where it is permitted. However, if the input VLAN
map (VLAN 10 map in
Figure 37-9
Host A
(VLAN 10)

Displaying IPv4 ACL Configuration

You can display the ACLs that are configured on the switch, and you can display the ACLs that have
been applied to interfaces and VLANs.
When you use the ip access-group interface configuration command to apply ACLs to a Layer 2 or 3
interface, you can display the access groups on the interface. You can also display the MAC ACLs
applied to a Layer 2 interface. You can use the privileged EXEC commands as described in
to display this information.
Table 37-2
Commands for Displaying Access Lists and Access Groups
Command
show access-lists [number | name]
show ip access-lists [number | name]
OL-21521-01
shows how ACLs are applied on packets that are replicated for IP multicasting. A multicast
Figure
37-9) drops the packet, no destination receives a copy of the packet.
Applying ACLs on Multicast Packets
VLAN 10
map
Frame
Host C
(VLAN 10)
VLAN 10
Purpose
Display the contents of one or all current IP and MAC address access lists
or a specific access list (numbered or named).
Display the contents of all current IP access lists or a specific IP access list
(numbered or named).
Input
Output
router
router
VLAN 20
ACL
ACL
Routing function
Packet
Catalyst 3750-X and 3560-X Switch Software Configuration Guide
Displaying IPv4 ACL Configuration
map
Host B
(VLAN 20)
VLAN 20
Table 37-2
37-41

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Catalyst 3560-x

Table of Contents