Using Vacls With Cisco Ios Acls - Cisco WS-X6066-SLB-APC - Content Switching Module Software Manual

Catalyst 6000 series software configuration guide
Hide thumbs Also See for WS-X6066-SLB-APC - Content Switching Module:
Table of Contents

Advertisement

Chapter 16
Configuring Access Control
NAT
NAT-required flows are handled in the software without impacting non-NAT flow forwarding in the
hardware.
Unicast RPF Check
The unicast RPF feature is supported in hardware on the PFC2. For ACL-based RPF checks, traffic
denied by the unicast RPF ACL is forwarded to the MSFC2 for RPF validation.
Caution
With ACL-based unicast RPF, packets denied by the ACL are sent to the CPU for RPF validation. In the
event of DOS attacks, these packets will most likely match the deny ACE and be forwarded to the CPU.
Under heavy traffic conditions, this could cause high CPU utilization.
Drop-suppress statistics for ACL-based RPF check is not supported.
Note
Bridge-Groups
Cisco IOS bridge-group ACLs are handled in the software.

Using VACLs with Cisco IOS ACLs

To access control both bridged and routed traffic, you can use VACLs only or a combination of
Cisco IOS ACLs and VACLs. You can define Cisco IOS ACLs on both input and output routed-VLAN
interfaces, and you can define a VACL to access control the bridged traffic.
If a flow matches a VACL deny or redirect clause in the ACL, irrespective of the IOS ACL
configuration, the flow is denied or redirected. The following caveats apply to IOS ACLs when used
with VACLs:
Note
VACLs have an implicit deny at the end of the list; a packet is denied if it does not match any VACL
ACE.
These sections describe Cisco IOS ACL and VACL configuration guidelines and guidelines for Layer 4
operations:
78-13315-02
Packets that require logging on the outbound ACLs are not logged if they are denied by a VACL.
NAT—VACLs are applied on packets before NAT translation. Note that if the translated flow
should not be access controlled, the flow might get access controlled after the translation because
of the VACL configuration.
Guidelines for Configuring Cisco IOS ACLs and VACLs on the Same VLAN Interface, page 16-16
Guidelines for Using Layer 4 Operations, page 16-20
Catalyst 6000 Family Software Configuration Guide—Releases 6.3 and 6.4
Using VACLs with Cisco IOS ACLs
16-15

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents