
Chapter 23 Configuring Network Security
Configuring VLAN ACLs
Multicast Packets
Figure 23-3 shows how ACLs are applied on packets that need multicast expansion. For packets that need multicast expansion, the ACLs are applied in the following order:
1.Packets that need multicast expansion:
a.VACL for input VLAN
b.Input Cisco IOS ACL
2.Packets after multicast expansion:
a.Output Cisco IOS ACL
b.VACL for output VLAN (not supported with PFC2)
3.Packets originating from router—VACL  for output VLAN
Figure 23-3  Applying VACLs on Multicast Packets
| 
 | Catalyst 6500 Series Switch | |
| 
 | with MSFC | |
| Routed | MSFC | |
| Input IOS ACL | 
 | |
| Bridged | 
 | |
| VACL | 
 | |
| Host A | Bridged | |
| (VLAN 10) | ||
| 
 | 
IOS ACL for output VLAN for packets originating from router
Output IOS ACL
VACL (Not supported on PFC2)
Host B
(VLAN 20)
26965
Host D
(VLAN 20)
Host C
(VLAN 10)
Configuring VACLs
These sections describe configuring VACLs:
•VACL Configuration Overview, page 
•Defining a VLAN Access Map, page 
•Configuring a Match Clause in a VLAN Access Map Sequence, page 
•Configuring an Action Clause in a VLAN Access Map Sequence, page 
•Applying a VLAN Access Map, page 
•Verifying VLAN Access Map Configuration, page 
| 
 | 
 | Cisco 7600 Series Router Cisco IOS Software Configuration  | 
 | 
 | |
| 
 | 
 | 
 | |||
| 
 | 
 | 
 | 
 | 
 | |
| 
 | 
 | 
 | 
 | ||