16-8
Catalyst 6000 Family Software Configuration Guide—Releases 6.3 and 6.4
78-13315-02
Chapter 16 Configuring Access Control
Applying Cisco IOS ACLs and VACLs on VLANs
Figure 16-2 Applying ACLs on Routed Packets
Multicast Packets
Figure 16-3
shows how ACLs are applied on packets that need multicast expansion. For packets that
need multicast expansion, the ACLs are applied in the following order:
1.
Packets that need multicast expansion:
a.
VACL for input VLAN
b.
Input Cisco IOS ACL
2.
Packets after multicast expansion:
a.
Output Cisco IOS ACL
b.
VACL for output VLAN
3.
Packets originating from router:
a.
VACL for output VLAN
Catalyst 6500 series switches
with MSFC
Host B
(VLAN 20)
Host A
(VLAN 10)
26964
Bridged
Bridged
VACL
VACL
Input IOS ACL
Output IOS ACL
Routed
MSFC