CHAPT ER
47-1
Software Configuration Guide—Release 15.0(2)SG
OL-23818-01
47
Configuring Network Security with ACLs
This chapter describes how to use access control lists (ACLs) to configure network security on the
Catalyst 4500 series switches.
Note The Catalyst 4500 series switch supports time-based ACLs.
Note For complete syntax and usage information for the switch commands used in this chapter, first look at
the Cisco Catalyst 4500 Series Switch Command Reference and related publications at this location:
http://www.cisco.com/en/US/products/hw/switches/ps4324/index.html
If the command is not found in the Catalyst 4500 Command Reference, it will be found in the larger
Cisco IOS library. Refer to the Cisco IOS Command Reference and related publications at this location:
http://www.cisco.com/en/US/products/ps6350/index.html
This chapter consists of the following major sections:
About ACLs, page 47-2
Hardware and Software ACL Support, page 47-6
TCAM Programming and ACLs for Supervisor Engine II-Plus, Supervisor Engine IV, Supervisor
Engine V, and Supervisor Engine V-10GE, page 47-7
TCAM Programming and ACLs for Supervisor Engine 6-E and Supervisor Engine 6L-E, page 47-16
Layer 4 Operators in ACLs, page 47-16
Configuring Unicast MAC Address Filtering, page 47-20
Configuring Named MAC Extended ACLs, page 47-20
Configuring EtherType Matching, page 47-22
Configuring Named IPv6 ACLs, page 47-23
Applying IPv6 ACLs to a Layer 3 Interface, page 47-24
Configuring VLAN Maps, page 47-24
Displaying VLAN Access Map Information, page 47-32