31-38
Cisco Catalyst Blade Switch 3020 for HP Software Configuration Guide
OL-8915-03
Chapter 31 Configuring Network Security with ACLs
Displaying IPv4 ACL Configuration
ACLs and Routed Packets
Figure 31-7
shows how ACLs are applied on routed packets. For routed packets, the ACLs are applied
in this order:
1.
VLAN map for input VLAN
2.
Input router ACL
3.
Output router ACL
4.
VLAN map for output VLAN
Figure 31-7
Applying ACLs on Routed Packets
Displaying IPv4 ACL Configuration
You can display the ACLs that are configured on the switch, and you can display the ACLs that have
been applied to interfaces and VLANs.
When you use the
ip access-group
interface configuration command to apply ACLs to a Layer 2 or 3
interface, you can display the access groups on the interface. You can also display the MAC ACLs
applied to a Layer 2 interface. You can use the privileged EXEC commands as described in
Table 31-2
to display this information.
Frame
Routing function
VLAN 10
Host A
(VLAN 10)
Packet
101359
VLAN 20
Host B
(VLAN 20)
VLAN 10
map
Input
router
ACL
Output
router
ACL
VLAN 20
map
Table 31-2
Commands for Displaying Access Lists and Access Groups
Command
Purpose
show access-lists
[
number | name
]
Display the contents of one or all current IP and MAC address access lists
or a specific access list (numbered or named).
show ip access-lists
[
number | name
]
Display the contents of all current IP access lists or a specific IP access list
(numbered or named).