32-40
Catalyst 3750 Switch Software Configuration Guide
OL-8550-02
Chapter 32 Configuring Network Security with ACLs
Displaying IPv4 ACL Configuration
ACLs and Multicast Packets
Figure 32-9
shows how ACLs are applied on packets that are replicated for IP multicasting. A multicast
packet being routed has two different kinds of filters applied: one for destinations that are other ports in
the input VLAN and another for each of the destinations that are in other VLANs to which the packet
has been routed. The packet might be routed to more than one output VLAN, in which case a different
router output ACL and VLAN map would apply for each destination VLAN.
The final result is that the packet might be permitted in some of the output VLANs and not in others. A
copy of the packet is forwarded to those destinations where it is permitted. However, if the input VLAN
map (VLAN 10 map in
Figure 32-9
) drops the packet, no destination receives a copy of the packet.
Figure 32-9
Applying ACLs on Multicast Packets
Displaying IPv4 ACL Configuration
You can display the ACLs that are configured on the switch, and you can display the ACLs that have
been applied to interfaces and VLANs.
When you use the
ip access-group
interface configuration command to apply ACLs to a Layer 2 or 3
interface, you can display the access groups on the interface. You can also display the MAC ACLs
applied to a Layer 2 interface. You can use the privileged EXEC commands as described in
Table 32-2
to display this information.
VLAN 10
map
Frame
Input
router
ACL
Output
router
ACL
Routing function
VLAN 10
VLAN 20
Host C
(VLAN 10)
Host A
(VLAN 10)
Host B
(VLAN 20)
VLAN 20
map
Packet
101360
Table 32-2
Commands for Displaying Access Lists and Access Groups
Command
Purpose
show access-lists
[
number | name
]
Display the contents of one or all current IP and MAC address access lists
or a specific access list (numbered or named).
show ip access-lists
[
number | name
]
Display the contents of all current IP access lists or a specific IP access list
(numbered or named).
Содержание 3750G - Catalyst Integrated Wireless LAN Controller
Страница 80: ...1 28 Catalyst 3750 Switch Software Configuration Guide OL 8550 02 Chapter 1 Overview Where to Go Next ...
Страница 606: ...27 8 Catalyst 3750 Switch Software Configuration Guide OL 8550 02 Chapter 27 Configuring UDLD Displaying UDLD Status ...
Страница 670: ...31 18 Catalyst 3750 Switch Software Configuration Guide OL 8550 02 Chapter 31 Configuring SNMP Displaying SNMP Status ...
Страница 1048: ...41 20 Catalyst 3750 Switch Software Configuration Guide OL 8550 02 Chapter 41 Configuring MSDP Monitoring and Maintaining MSDP ...
Страница 1086: ...43 26 Catalyst 3750 Switch Software Configuration Guide OL 8550 02 Chapter 43 Troubleshooting Using the crashinfo Files ...
Страница 1104: ...B 4 Catalyst 3750 Switch Software Configuration Guide OL 8550 02 Appendix B Supported MIBs Using FTP to Access the MIB Files ...