Forward
Sends the traffic to the destination determined by the normal operation of the device.
Redirect
Redirects the traffic to one or more specified interfaces.
Drop
Drops the traffic. If you specify drop as the action, you can also specify that the device logs the dropped
packets.
VACL Statistics
The device can maintain global statistics for each rule in a VACL. If a VACL is applied to multiple VLANs,
the maintained rule statistics are the sum of packet matches (hits) on all the interfaces on which that VACL
is applied.
The device does not support interface-level VACL statistics.
Note
For each VLAN access map that you configure, you can specify whether the device maintains statistics for
that VACL. This feature allows you to turn VACL statistics on or off as needed to monitor traffic filtered by
a VACL or to help troubleshoot VLAN access-map configuration.
Session Manager Support for VACLs
Session Manager supports the configuration of VACLs. This feature allows you to verify the ACL configuration
and confirm that the resources required by the configuration are available prior to committing them to the
running configuration. For more information about Session Manager, see the
Cisco Nexus 9000 Series NX-OS
System Management Configuration Guide
.
Licensing Requirements for VACLs
This table shows the licensing requirements for this feature.
License Requirement
Product
VACLs require no license. Any feature not included in a license package is bundled with the
image and is provided at no extra charge to you. For an explanation of the Cisco NX-OS
licensing scheme, see the
Cisco NX-OS Licensing Guide
.
Cisco NX-OS
Prerequisites for VACLs
VACLs have the following prerequisite:
• Ensure that the IP ACL or MAC ACL that you want to use in the VACL exists and is configured to filter
traffic in the manner that you need for this application.
Cisco Nexus 9000 Series NX-OS Security Configuration Guide, Release 9.x
296
Configuring VLAN ACLs
VACL Statistics