15-8
Catalyst 6500 Series Switch Software Configuration Guide—Release 8.7
OL-8978-04
Chapter 15 Configuring Access Control
Applying Cisco IOS ACLs and VACLs on VLANs
Figure 15-1
Applying ACLs on Bridged Packets
Routed Packets
Figure 15-2
shows how the ACLs are applied on the routed/Layer 3-switched packets. For the
routed/Layer 3-switched packets, the ACLs are applied in the following order:
1.
VACL for input VLAN
2.
Input Cisco IOS ACL
3.
Output Cisco IOS ACL
4.
VACL for output VLAN
Figure 15-2
Applying ACLs on Routed Packets
Multicast Packets
Figure 15-3
shows how the ACLs are applied on the packets that need multicast expansion. For the
packets that need multicast expansion, the ACLs are applied in the following order:
1.
Packets that need multicast expansion:
a.
VACL for input VLAN
b.
Input Cisco IOS ACL
Catalyst 6500 Series Switch
with PFC
Host B
(VLAN 10)
Host A
(VLAN 10)
26961
VACL
VACL
Bridged
Catalyst 6500 series switches
with MSFC
Host B
(VLAN 20)
Host A
(VLAN 10)
26964
Bridged
Bridged
VACL
VACL
Input IOS ACL
Output IOS ACL
Routed
MSFC