35-38
Cisco Catalyst Blade Switch 3130 and 3032 for Dell Software Configuration Guide
OL-13270-06
Chapter 35 Configuring Network Security with ACLs
Using VLAN Maps with Router ACLs
Note
For complete syntax and usage information of the commands used in this section, see the
Cisco IOS LAN
Switching Command Reference
:
http://www.cisco.com/en/US/docs/ios/lanswitch/command/reference/lsw_book.html
Using VLAN Maps with Router ACLs
To access control both bridged and routed traffic, you can use VLAN maps only or a combination of
router ACLs and VLAN maps. You can define router ACLs on both input and output routed VLAN
interfaces, and you can define a VLAN map to access control the bridged traffic.
If a packet flow matches a VLAN-map deny clause in the ACL, regardless of the router ACL
configuration, the packet flow is denied.
Note
When you use router ACLs with VLAN maps, packets that require logging on the router ACLs are not
logged if they are denied by a VLAN map.
If the VLAN map has a match clause for the type of packet (IP or MAC) and the packet does not match
the type, the default is to drop the packet. If there is no match clause in the VLAN map, and no action
specified, the packet is forwarded if it does not match any VLAN map entry.
These sections contain information about using VLAN maps with router ACLs:
•
VLAN Maps and Router ACL Configuration Guidelines, page 35-39
•
Examples of Router ACLs and VLAN Maps Applied to VLANs, page 35-39