
Chapter 23 Configuring Network Security
Configuring VLAN ACLs
Routed Packets
Figure 23-2 shows how ACLs are applied on routed and Layer 3-switched  packets. For routed or Layer 3-switched  packets, the ACLs are applied in the following order:
1.VACL for input VLAN
2.Input Cisco IOS ACL
3.Output Cisco IOS ACL
4.VACL for output VLAN
Figure 23-2  Applying VACLs on Routed Packets
| 
 | Routed | |
| Input IOS ACL | Output IOS ACL | |
| MSFC | ||
| 
 | ||
| Bridged | VACL | |
| 
 | ||
| VACL | Bridged | |
| 
 | ||
| 
 | Catalyst 6500 series switches | |
| 
 | with MSFC | |
| Host A | Host B | |
| (VLAN 20) | ||
| (VLAN 10) | ||
| 
 | 
26964
| 
 | Cisco 7600 Series Router Cisco IOS Software Configuration  | 
| 
 |