Chapter 34 Configuring Network Security with ACLs

Displaying IPv4 ACL Configuration

ACLs and Multicast Packets

Figure 34-9shows how ACLs are applied on packets that are replicated for IP multicasting. A multicast packet being routed has two different kinds of filters applied: one for destinations that are other ports in the input VLAN and another for each of the destinations that are in other VLANs to which the packet has been routed. The packet might be routed to more than one output VLAN, in which case a different router output ACL and VLAN map would apply for each destination VLAN.

The final result is that the packet might be permitted in some of the output VLANs and not in others. A copy of the packet is forwarded to those destinations where it is permitted. However, if the input VLAN map (VLAN 10 map in Figure 34-9) drops the packet, no destination receives a copy of the packet.

Figure 34-9 Applying ACLs on Multicast Packets

 

Input

Output

 

VLAN 10

router

router

VLAN 20

map

ACL

ACL

map

Frame

 

 

 

Host A

 

 

Host B

(VLAN 10)

 

 

(VLAN 20)

 

Routing function

 

Host C (VLAN 10)

VLAN 10

Packet

 

VLAN 20

101360

Displaying IPv4 ACL Configuration

You can display the ACLs that are configured on the switch, and you can display the ACLs that have been applied to interfaces and VLANs.

When you use the ip access-groupinterface configuration command to apply ACLs to a Layer 2 or 3 interface, you can display the access groups on the interface. You can also display the MAC ACLs applied to a Layer 2 interface. You can use the privileged EXEC commands as described in Table 34-2to display this information.

Table 34-2 Commands for Displaying Access Lists and Access Groups

 

Command

Purpose

 

 

 

 

show access-lists [number name]

Display the contents of one or all current IP and MAC address access lists

 

 

 

 

or a specific access list (numbered or named).

 

 

 

 

show ip access-lists [number name]

Display the contents of all current IP access lists or a specific IP access list

 

 

 

 

(numbered or named).

 

 

 

 

 

 

 

 

Catalyst 3750-E and 3560-E Switch Software Configuration Guide

 

 

 

 

34-40

 

 

OL-9775-02

 

 

 

 

 

Page 738
Image 738
Cisco Systems 3750E Displaying IPv4 ACL Configuration, ACLs and Multicast Packets, Show ip access-lists number name, 34-40