data:image/s3,"s3://crabby-images/01008/01008caa8f3c9f78d0cfcb316be9f22f29d34479" alt="Cisco 6500 - Catalyst Series 10 Gigabit EN Interface Module Expansion Скачать руководство пользователя страница 236"
13-10
Catalyst 6500 Series Switch and Cisco 7600 Series Router Firewall Services Module Configuration Guide using ASDM
OL-20748-01
Chapter 13 Identifying Traffic with Access Lists
Adding an EtherType Access List
Using Extended and EtherType Access Lists on the Same Interface
You can apply only one access list of each type (extended and EtherType) to each direction of an
interface. You can also apply the same access lists on multiple interfaces.
Allowing MPLS
If you allow MPLS, ensure that Label Distribution Protocol and Tag Distribution Protocol TCP
connections are established through the FWSM by configuring both MPLS routers connected to the
FWSM to use the IP address on the FWSM interface as the router-id for LDP or TDP sessions. (LDP and
TDP allow MPLS routers to negotiate the labels (addresses) used to forward packets.)
On Cisco IOS routers, enter the appropriate command for your protocol, LDP or TDP. The
interface
is
the interface connected to the FWSM.
hostname(config)#
mpls ldp router-id
interface
force
Or
hostname(config)#
tag-switching tdp router-id
interface
force
Adding an EtherType ACE
To add an EtherType ACE, enter the following command:
hostname(config)#
access-list
access_list_name
ethertype
{
permit
|
deny
} {
ipx
|
bpdu
|
mpls-unicast
|
mpls-multicast
|
any
|
hex_number
}
The
hex_number
is any EtherType that can be identified by a 16-bit hexadecimal number greater than or
equal to 0x600. See RFC 1700, “Assigned Numbers,” at
http://www.ietf.org/rfc/rfc1700.txt
for a list of
EtherTypes.
When you enter the
access-list
command for a given access list name, the ACE is added to the end of
the access list.
Tip
Enter the
access_list_name
in upper case letters so the name is easy to see in the configuration. You
might want to name the access list for the interface (for example, INSIDE), or for the purpose (for
example, MPLS or IPX).
For example, the following sample access list allows common EtherTypes originating on the inside
interface:
hostname(config)#
access-list ETHER ethertype permit ipx
hostname(config)#
access-list ETHER ethertype permit bpdu
hostname(config)#
access-list ETHER ethertype permit mpls-unicast
hostname(config)#
access-group ETHER in interface inside
The following access list allows some EtherTypes through the FWSM, but denies IPX:
hostname(config)#
access-list ETHER ethertype deny ipx
hostname(config)#
access-list ETHER ethertype permit 0x1234
hostname(config)#
access-list ETHER ethertype permit bpdu
hostname(config)#
access-list ETHER ethertype permit mpls-unicast
hostname(config)#
access-group ETHER in interface inside
hostname(config)#
access-group ETHER in interface outside
Содержание 6500 - Catalyst Series 10 Gigabit EN Interface Module Expansion
Страница 35: ...P A R T 1 Getting Started and General Information ...
Страница 36: ......
Страница 297: ...P A R T 2 Configuring the Security Policy ...
Страница 298: ......
Страница 521: ...P A R T 3 System Administration ...
Страница 522: ......
Страница 613: ...P A R T 4 Reference ...
Страница 614: ......