16-2
Catalyst 6000 Family Software Configuration Guide—Releases 6.3 and 6.4
78-13315-02
Chapter 16 Configuring Access Control
Hardware Requirements
Switching [MLS]). The switch first bridges the packet, the packet is then routed internally without going
to the router, and then the packet is bridged again to send it to its destination. During this process, the
switch can access control
all
packets it switches,
including
packets bridged within a VLAN.
Cisco IOS ACLs provide access control for routed traffic between VLANs, and VLAN ACLs (VACLs)
provide access control for
all
packets.
Standard and extended Cisco IOS ACLs are used to classify packets. Classified packets can be subject
to a number of features such as access control (security), encryption, policy-based routing, and so on.
Standard and extended Cisco IOS ACLs are only configured on router interfaces and applied on routed
packets.
VACLs can provide access control based on Layer 3 addresses for IP and IPX protocols. Unsupported
protocols are access controlled through MAC addresses. A VACL is applied to all packets (bridged and
routed) and can be configured on any VLAN interface. Once a VACL is configured on a VLAN, all
packets (routed or bridged) entering the VLAN are checked against the VACL. Packets can either enter
the VLAN through a switch port or through a router port after being routed.
Hardware Requirements
The hardware that is required to configure ACLs on Catalyst 6000 family switches is as follows:
•
Cisco IOS ACLs:
–
Policy Feature Card (PFC) and MSFC or MSFC2
–
PFC2 and MSFC2
•
VACLs and QoS ACLs:
–
PFC
–
PFC2
Note
The QoS feature set supported on your switch is determined by which switching engine daughter card
is installed on the supervisor engine. See
Chapter 41, “Configuring QoS”
for more information.
Supported ACLs
These sections describe the ACLs supported by the Catalyst 6000 family switches:
•
QoS ACLs, page 16-2
•
Cisco IOS ACLs, page 16-3
•
VACLs, page 16-3
QoS ACLs
You can configure QoS ACLs on the switch; see
Chapter 41, “Configuring QoS.”