Cisco Systems 7600 SERIES manual Configuring Vacl Logging, 23-17

Page 17

Chapter 23 Configuring Network Security

Configuring VLAN ACLs

When configuring a capture port, note the following syntax information:

With Release 12.1(13)E and later releases, you can configure any port as a capture port. With earlier releases, only the Gigabit Ethernet monitor port on the IDS module can be configured as a capture port.

When configuring a capture port with Release 12.1(13)E and later releases, note the following syntax information:

The vlan_list parameter can be a single VLAN ID or a comma-separated list of VLAN IDs or VLAN ID ranges (vlan_IDvlan_ID).

To encapsulate captured traffic, configure the capture port with the switchport trunk encapsulation command (see the “Configuring a Layer 2 Switching Port as a Trunk” section on page 7-8) before you enter the switchport capture command.

To not encapsulate captured traffic, configure the capture port with the switchport mode access command (see the “Configuring a LAN Interface as a Layer 2 Access Port” section on

page 7-14) before you enter the switchport capture command.

The capture port supports only egress traffic. No traffic can enter the router through a capture port.

This example shows how to configure a Fast Ethernet interface 5/1 as a capture port:

Router(config)# interface gigabitEthernet 5/1

Router(config-if)# switchport capture

Router(config-if)# end

This example shows how to display VLAN access map information:

Router# show vlan access-map mordred

Vlan access-map "mordred" 10 match: ip address net_10 action: forward capture

Router#

This example shows how to display mappings between VACLs and VLANs. For each VACL map, there is information about the VLANs that the map is configured on and the VLANs that the map is active on. A VACL is not active if the VLAN does not have an interface.

Router# show vlan filter

VLAN Map mordred:

Configured on VLANs: 2,4-6

Active on VLANs: 2,4-6

Router#

Configuring VACL Logging

When you configure VACL logging, IP packets that are denied generate log messages in these situations:

When the first matching packet is received

For any matching packets received during the last 5-minute interval

If the threshold is reached before the 5-minute interval

Log messages are generated on a per-flow basis. A flow is defined as packets with the same IP addresses and Layer 4 (UDP or TCP) port numbers. When a log message is generated, the timer and packet count is reset.

 

 

Cisco 7600 Series Router Cisco IOS Software Configuration Guide—12.1E

 

 

 

 

 

 

78-14064-04

 

 

23-17

 

 

 

 

 

Image 17
Contents 23-1 ACL Configuration GuidelinesThis chapter consists of these sections 23-2 Hardware and Software ACL Support23-3 Determining Layer 4 Operation UsageDetermining Logical Operation Unit Usage Configuring the Cisco IOS Firewall Feature SetMore detailed example follows 23-423-5 Cisco IOS Firewall Feature Set Support OverviewConfiguring Cbac on Cisco 7600 Series Routers Firewall Configuration Guidelines and RestrictionsRestrictions Guidelines23-7 Configuring MAC Address-Based Traffic BlockingUnderstanding VACLs Configuring Vlan ACLsVacl Overview 23-8Bridged Packets VACLs and Cbac cannot be configured on the same interfaceSame interface Igmp packets are not checked against VACLs23-10 Routed PacketsThese sections describe configuring VACLs Configuring VACLsMulticast Packets 23-11Defining a Vlan Access Map Vacl Configuration OverviewTo define a Vlan access map, perform this task 23-12Configures the match clause in a Vlan access map sequence Configuring a Match Clause in a Vlan Access Map SequenceDeletes the match clause in a Vlan access map sequence 23-1323-14 Configuring an Action Clause in a Vlan Access Map SequenceApplying a Vlan Access Map 23-15 Verifying Vlan Access Map ConfigurationVlan Access Map Configuration and Verification Examples 23-16 Configuring a Capture Port23-17 Configuring Vacl Logging23-18 Configuring TCP InterceptConfiguring Unicast RPF Configuring Unicast Reverse Path ForwardingUnderstanding Unicast RPF Support Enabling Self-Pinging23-20 Configuring the Unicast RPF Checking Mode23-21 Configuring Unicast Flood ProtectionThis example shows how to verify the configuration 23-22 Configuring MAC Move Notification23-23 23-24
Related manuals
Manual 74 pages 38.06 Kb