24-13
Catalyst 2360 Switch Software Configuration Guide
OL-19808-01
Chapter 24 Managing Network Security with ACLs
Configuring IPv4 ACLs
Beginning in privileged EXEC mode, follow these steps to restrict incoming and outgoing connections
between a virtual terminal line and the addresses in an ACL:
To remove an ACL from a terminal line, use the
no access-class
access-list-number
{
in
|
out
} line
configuration command.
Applying an IPv4 ACL to a Management VLAN
Note
This section describes how to apply IPv4 ACLs to a management VLAN. By default, the router sends
Internet Control Message Protocol (ICMP) unreachable messages when a packet is denied by an access
group. These access-group denied packets are not dropped in hardware but are bridged to the switch CPU
so that it can generate the ICMP-unreachable message.
Beginning in privileged EXEC mode, follow these steps to control access to an interface:
Command
Purpose
Step 1
configure terminal
Enter global configuration mode.
Step 2
line
[
console
|
vty
]
line-number
Identify a specific line to configure, and enter in-line configuration mode.
•
console
—Specify the console terminal line. The console port is DCE.
•
vty
—Specify a virtual terminal for remote console access.
The
line-number
is the first line number in a contiguous group that you want
to configure when the line type is specified. The range is from 0 to 16.
Step 3
access-class
access-list-number
{
in
|
out
}
Restrict incoming and outgoing connections between a particular virtual
terminal line (into a device) and the addresses in an access list.
Step 4
end
Return to privileged EXEC mode.
Step 5
show running-config
Display the access list configuration.
Step 6
copy running-config startup-config
(Optional) Save your entries in the configuration file.
Command
Purpose
Step 1
configure terminal
Enter global configuration mode.
Step 2
interface vlan 1
Configure management VLAN.
Step 3
ip access-group
{
access-list-number |
name
}
in
Control access to the specified interface.
Step 4
end
Return to privileged EXEC mode.
Step 5
show running-config
Display the access list configuration.
Step 6
copy running-config startup-config
(Optional) Save your entries in the configuration file.