16-9
Catalyst 6000 Family Software Configuration Guide—Releases 6.3 and 6.4
78-13315-02
Chapter 16 Configuring Access Control
Using Cisco IOS ACLs in your Network
Figure 16-3 Applying ACLs on Multicast Packets
Using Cisco IOS ACLs in your Network
Note
Configuring Cisco IOS ACLs on the Catalyst 6000 family switch routed-VLAN interfaces is the
same as configuring ACLs on other Cisco routers. To configure Cisco IOS ACLs, see the
“Unsupported Features” section on page 16-27
and the
“VACL Configuration Guidelines” section on
page 16-28
. In addition, refer to the Cisco IOS configuration guides and command reference
publication. For example, to configure ACLs for IP, refer to the “Configuring IP Services” chapter in
the
Network Protocols Configuration Guide
, Part 1.
When a feature is configured on the router to process traffic (such as NAT), the Cisco IOS ACL
associated with the feature determines the specific traffic that is bridged to the router instead of being
Layer 3 switched. The router then applies the feature and routes the packet normally. Note that there are
some exceptions to this process as described in the
“Hardware and Software Handling of Cisco IOS
ACLs with PFC” section on page 16-10
.
Note
In systems with redundant MSFCs, the ACL configurations for Cisco IOS ACLs and VACLs must be
the same on both MSFCs.
Catalyst 6500 Series Switch
with MSFC
Host B
(VLAN 20)
Host D
(VLAN 20)
Host A
(VLAN 10)
Host C
(VLAN 10)
26965
Bridged
Bridged
VACL
VACL (Not supported
on PFC2)
Input IOS ACL
Output IOS ACL
Routed
MSFC
IOS ACL for
output VLAN
for packets
originating from
router