16-4
Catalyst 6000 Family Software Configuration Guide—Releases 6.3 and 6.4
78-13315-02
Chapter 16 Configuring Access Control
Supported ACLs
You can configure VACLs on Layer 3 addresses for IP and IPX. All other protocols are access controlled
through MAC addresses and Ethertype using MAC VACLs.
Caution
IP traffic and IPX traffic are not access controlled by MAC VACLs. All other traffic types
(AppleTalk, DECnet, and so on) are classified as MAC traffic and MAC VACLs are used to access
control this traffic.
You can enforce VACLs only on packets going through the Catalyst 6000 family switch; you cannot
enforce VACLs on traffic between hosts on a hub or another switch connected to the Catalyst 6000
family switch.
ACEs Supported in VACLs
A VACL contains an ordered list of access control entries (ACEs). Each VACL can contain ACEs of only
one type. Each ACE contains a number of fields that are matched against the contents of a packet. Each
field can have an associated bit mask to indicate which bits are relevant. An action is associated with
each ACE that describes what the system should do with the packet when a match occurs. The action is
feature dependent. Catalyst 6000 family switches support three types of ACEs in the hardware:
•
IP ACEs
•
IPX ACEs
•
Ethernet ACEs
Table 16-1
lists the parameters associated with each ACE type.
Table 16-1 ACE Types and Parameters
ACE Type
TCP or UDP
1
ICMP
1
Other IP
1
IPX
Ethernet
2
Layer 4
parameters
Source port
Source port
operator
Destination
port
Destination
port operator
ICMP code
1
N/A
ICMP type
N/A
Layer 3
parameters
IP ToS byte
IP ToS byte
IP ToS byte
IP source
address
IP source
address
IP source
address
IPX source
network
IP destination
address
IP destination
address
IP destination
address
IPX destination
network
IPX destination
node
TCP or UDP
ICMP
Other protocol
IPX packet type