15-5
Catalyst 6500 Series Switch Software Configuration Guide—Release 8.7
OL-8978-04
Chapter 15 Configuring Access Control
Supported ACLs
ACEs Supported in VACLs
A VACL contains an ordered list of access control entries (ACEs). Each VACL can contain ACEs of only
one type. Each ACE contains a number of fields that are matched against the contents of a packet. Each
field can have an associated bit mask to indicate which bits are relevant. An action is associated with
each ACE that describes what the system should do with the packet when a match occurs. The action is
feature dependent. Catalyst 6500 series switches support three types of ACEs in the hardware:
•
IP ACEs
•
IPX ACEs
•
Ethernet ACEs
Table 15-1
lists the parameters that are associated with each ACE type.
Table 15-1
ACE Types and Parameters
ACE Type
TCP or UDP
1
1.
IP ACEs.
ICMP
1
Other IP
1
IPX
Ethernet
2
2.
For Ethernet packets that are not IP version 4 or IPX.
Layer 4
parameters
Source port
Source port
operator
Destination
port
Destination
port operator
ICMP code
1
N/A
ICMP type
N/A
Layer 3
parameters
IP ToS byte
IP ToS byte
IP ToS byte
IP source
address
IP source
address
IP source
address
IPX source
network
IP destination
address
IP destination
address
IP destination
address
IPX destination
network
IPX destination
node
TCP or UDP
ICMP
Other protocol
IPX packet type
Layer 2
parameters
EtherType
Ethernet
source
address
Ethernet
destination
address