34-33
Catalyst 3750-E and 3560-E Switch Software Configuration Guide
OL-9775-02
Chapter34 Configuring Network Securi ty with ACLs
Configuring VLAN Maps
Example 3
In this example, the VLAN map has a default action of drop fo r MAC packets and a default action of
forward for IP packets. Used with MAC extended access lists good-hosts and good-protocols, the map
will have the following results:
Forward MAC packets from hosts 0000.0c00.0111 and 0000.0c00.0211
Forward MAC packets with decnet-iv or vines-ip protocols
Drop all other non-IP packets
Forward all IP packets
Switch(config)# mac access-list extended good-hosts
Switch(config-ext-macl)# permit host 000.0c00.0111 any
Switch(config-ext-macl)# permit host 000.0c00.0211 any
Switch(config-ext-nacl)# exit
Switch(config)# mac access-list extended good-protocols
Switch(config-ext-macl)# permit any any decnet-ip
Switch(config-ext-macl)# permit any any vines-ip
Switch(config-ext-nacl)# exit
Switch(config)# vlan access-map drop-mac-default 10
Switch(config-access-map)# match mac address good-hosts
Switch(config-access-map)# action forward
Switch(config-access-map)# exit
Switch(config)# vlan access-map drop-mac-default 20
Switch(config-access-map)# match mac address good-protocols
Switch(config-access-map)# action forward
Example 4
In this example, the VLAN map has a default action of drop for a ll packets (IP and non-IP). Used with
access lists tcp-match and good-hosts from Examples 2 and 3, the map wil l have the following results:
Forward all TCP packets
Forward MAC packets from hosts 0000.0c00.0111 and 0000.0c00.0211
Drop all other IP packets
Drop all other MAC packets
Switch(config)# vlan access-map drop-all-default 10
Switch(config-access-map)# match ip address tcp-match
Switch(config-access-map)# action forward
Switch(config-access-map)# exit
Switch(config)# vlan access-map drop-all-default 20
Switch(config-access-map)# match mac address good-hosts
Switch(config-access-map)# action forward