Chapter 34 Configuring Network Security with ACLs

Using VLAN Maps with Router ACLs

Figure 34-7 Applying ACLs on Bridged Packets

VLAN 10

 

VLAN 20

 

map

 

map

 

Frame

 

 

 

Host A

 

Host B

 

(VLAN 10)

 

(VLAN 20)

 

Fallback bridge

 

 

VLAN 10

Packet

VLAN 20

101358

 

 

 

 

 

ACLs and Routed Packets

Figure 34-8shows how ACLs are applied on routed packets. For routed packets, the ACLs are applied in this order:

1.VLAN map for input VLAN

2.Input router ACL

3.Output router ACL

4.VLAN map for output VLAN

Figure 34-8 Applying ACLs on Routed Packets

 

Input

Output

 

 

VLAN 10

router

router

VLAN 20

 

map

ACL

ACL

map

 

Frame

 

 

 

 

Host A

 

 

Host B

 

(VLAN 10)

 

 

(VLAN 20)

 

Routing function

 

 

VLAN 10

 

Packet

VLAN 20

101359

 

 

 

 

 

 

 

Catalyst 3750-E and 3560-E Switch Software Configuration Guide

 

OL-9775-02

34-39

 

 

 

Page 737
Image 737
Cisco Systems 3750E manual ACLs and Routed Packets, 34-39