
Access Control Lists (ACLs) for the Series 5300xl Switches
Overview
6. Assign the ACLs to filter the inbound and/or outbound traffic on static
VLAN interfaces configured on the switch.
7. Enable IP routing on the switch. (Except for an ACL configured to filter
traffic having the switch itself as the destination IP address, IP routing
must be enabled before ACLs will operate.)
8. Test for desired results.
For more details on ACL planning considerations, refer to “Planning an ACL
Application” on page 9-16.
Notes on IP Routing
To activate an ACL to screen inbound traffic for routing between subnets,
assign the ACL to the statically configured VLAN on which the traffic enters
the switch. Also, ensure that IP routing is enabled. Similarly, to activate an
ACL to screen routed, outbound traffic, assign the ACL to the statically
configured VLAN on which the traffic exits from the switch. The only excep
tion to these rules is for an ACL configured to screen inbound traffic with a
destination IP address on the switch. In this case, an ACL assigned to a VLAN
screens traffic addressed to an IP address on the switch, regardless of whether
IP routing is also enabled. (ACLs do not screen outbound traffic generated by
the switch, itself. Refer to “ACL Screening of Traffic Generated by the Switch”
on page 9-63.)
Caution Regarding
Source routing is enabled by default on the switch and can be used to override
the Use of Source
ACLs. For this reason, if you are using ACLs to enhance network security, the
Routing
recommended action is to use the
no ip source-route
command to disable
source routing on the switch. (If source routing is disabled in the running
config file, the
show running
command includes “
no ip source-route
” in the
running-config file listing.)
9-11
Summary of Contents for 6400cl
Page 2: ......
Page 84: ...Static Virtual LANs VLANs VLAN Restrictions This page is intentionally unused 2 54 ...
Page 104: ...GVRP GVRP Operating Notes This page intentionally unused 3 20 ...
Page 274: ...Switch Meshing Operating Notes for Switch Meshing This page is intentionally unused 7 28 ...
Page 662: ... This page is intentionally unused 20 Index ...
Page 663: ......