62-24
Catalyst 4500 Series Switch, Cisco IOS Software Configuration Guide - Cisco IOS XE 3.9.xE and IOS 15.2(5)Ex
Chapter 62 Configuring Network Security with ACLs
Configuring VLAN Maps
Example 2
In this example, the VLAN map is configured to drop IP packets and to forward MAC packets by default.
By applying standard ACL 101 and the extended named access lists
igmp-match
and
tcp-match
, the
VLAN map is configured to do the following:
•
Forward all UDP packets
•
Drop all IGMP packets
•
Forward all TCP packets
•
Drop all other IP packets
•
Forward all non-IP packets
Switch(config)#
access-list 101 permit udp any any
Switch(config)#
ip access-list extended igmp-match
Switch(config-ext-nacl)#
permit igmp any any
Switch(config)#
ip access-list extended tcp-match
Switch(config-ext-nacl)#
permit tcp any any
Switch(config-ext-nacl)#
exit
Switch(config)#
vlan access-map drop-ip-default 10
Switch(config-access-map)#
match ip address 101
Switch(config-access-map)#
action forward
Switch(config-access-map)#
exit
Switch(config)#
vlan access-map drop-ip-default 20
Switch(config-access-map)#
match ip address igmp-match
Switch(config-access-map)#
action drop
Switch(config-access-map)#
exit
Switch(config)#
vlan access-map drop-ip-default 30
Switch(config-access-map)#
match ip address tcp-match
Switch(config-access-map)#
action forward
Example 3
In this example, the VLAN map is configured to drop MAC packets and forward IP packets by default.
By applying MAC extended access lists,
good-hosts
and
good-protocols
, the VLAN map is configured
to do the following:
•
Forward MAC packets from hosts 0000.0c00.0111 and 0000.0c00.0211
•
Forward MAC packets of DECnet or VINES (Virtual Integrated Network Service) protocol-family
•
Drop all other non-IP packets
•
Forward all IP packets
Switch(config)#
mac access-list extended good-hosts
Switch(config-ext-macl)#
permit host 000.0c00.0111 any
Switch(config-ext-macl)#
permit host 000.0c00.0211 any
Switch(config-ext-nacl)#
exit
Switch(config)#
mac access-list extended good-protocols
Switch(config-ext-macl)#
permit any any protocol-family decnet
Switch(config-ext-macl)#
permit any any protocol-family vines
Switch(config-ext-nacl)#
exit
Switch(config)#
vlan access-map drop-mac-default 10
Switch(config-access-map)#
match mac address good-hosts
Switch(config-access-map)#
action forward
Switch(config-access-map)#
exit
Switch(config)#
vlan access-map drop-mac-default 20
Switch(config-access-map)#
match mac address good-protocols
Switch(config-access-map)#
action forward
Содержание Catalyst 4500 Series
Страница 2: ......
Страница 4: ......
Страница 2086: ...Index IN 46 Software Configuration Guide Release IOS XE 3 9 0E and IOS 15 2 5 E ...