16-7
Catalyst 6000 Family Software Configuration Guide—Releases 6.3 and 6.4
78-13315-02
Chapter 16 Configuring Access Control
Applying Cisco IOS ACLs and VACLs on VLANs
Applying Cisco IOS ACLs and VACLs on VLANs
This section describes how to apply Cisco IOS ACLs and VACLs to the VLAN for bridged packets,
routed packets, and multicast packets.
These sections show how ACLs and VACLs are applied:
•
Bridged Packets, page 16-7
•
Routed Packets, page 16-7
•
Multicast Packets, page 16-8
Bridged Packets
Figure 16-1
shows how an ACL is applied on bridged packets. For bridged packets, only Layer 2 ACLs
are applied to the input VLAN.
Figure 16-1 Applying ACLs on Bridged Packets
Routed Packets
Figure 16-2
shows how ACLs are applied on routed/Layer 3-switched packets. For
routed/Layer 3-switched packets, the ACLs are applied in the following order:
1.
VACL for input VLAN
2.
Input Cisco IOS ACL
3.
Output Cisco IOS ACL
4.
VACL for output VLAN
Catalyst 6500 Series Switch
with PFC
Host B
(VLAN 10)
Host A
(VLAN 10)
26961
VACL
Bridged