Switch(config)#
vlan access-map drop-ip-default 20
Switch(config-access-map)#
match ip address igmp-match
Switch(config-access-map)#
action drop
Switch(config-access-map)#
exit
Switch(config)#
vlan access-map drop-ip-default 30
Switch(config-access-map)#
match ip address tcp-match
Switch(config-access-map)#
action forward
Example: Default Action of Dropping MAC Packets and Forwarding IP Packets
In this example, the VLAN map has a default action of drop for MAC packets and a default action of forward
for IP packets. Used with MAC extended access lists
good-hosts
and
good-protocols
, the map will have the
following results:
•
Forward MAC packets from hosts 0000.0c00.0111 and 0000.0c00.0211
•
Forward MAC packets with decnet-iv or vines-ip protocols
•
Drop all other non-IP packets
•
Forward all IP packets
Switch(config)#
mac access-list extended good-hosts
Switch(config-ext-macl)#
permit host 000.0c00.0111 any
Switch(config-ext-macl)#
permit host 000.0c00.0211 any
Switch(config-ext-nacl)#
exit
Switch(config)#
action forward
Switch(config-ext-macl)#
mac access-list extended good-protocols
Switch(config-ext-macl)#
permit any any vines-ip
Switch(config-ext-nacl)#
exit
Switch(config)#
vlan access-map drop-mac-default 10
Switch(config-access-map)#
match mac address good-hosts
Switch(config-access-map)#
action forward
Switch(config-access-map)#
exit
Switch(config)#
vlan access-map drop-mac-default 20
Switch(config-access-map)#
match mac address good-protocols
Switch(config-access-map)#
action forward
Example: Default Action of Dropping All Packets
In this example, the VLAN map has a default action of drop for all packets (IP and non-IP). Used with access
lists
tcp-match
and
good-hosts
from Examples 2 and 3, the map will have the following results:
•
Forward all TCP packets
•
Forward MAC packets from hosts 0000.0c00.0111 and 0000.0c00.0211
•
Drop all other IP packets
•
Drop all other MAC packets
Switch(config)#
vlan access-map drop-all-default 10
Switch(config-access-map)#
match ip address tcp-match
Switch(config-access-map)#
action forward
Switch(config-access-map)#
exit
Switch(config)#
vlan access-map drop-all-default 20
Switch(config-access-map)#
match mac address good-hosts
Switch(config-access-map)#
action forward
Catalyst 2960-XR Switch Security Configuration Guide, Cisco IOS Release 15.0(2)EX1
148
OL-29434-01
Configuring IPv4 ACLs
Configuration Examples for ACLs and VLAN Maps