47-43
Software Configuration Guide—Release 15.0(2)SG
OL-23818-01
Chapter 47 Configuring Network Security with ACLs Configuring RA Guard
Scenario 3: Host A is connected to an interface in VLAN 10, which has a VACL and an SVI configured.
The SVI has an input Router ACL configured and the interface has an input PACL config ured, as shown
in Figure 47-9:
Figure 47-9 Scenario 3: VACL and Input Router ACL
If the interface access group mode is prefer port, then only the input PACL is applied on the ingress
traffic from Host A. If the mode is prefer VLAN, then the merged results of the VACL and the input
Router ACL are applied to the ingress traffic from Host A. If the mode is merge, the input PACL is first
applied to the ingress traffic from Host A, the VACL is applied on the traffic and finally, and the input
Router ACL is applied to the traffic that needs routing. (that is, the merged results of the input PACL,
VACL, and input Router ACL are applied to the traffic).
Configuring RA Guard
This section includes these topics:
Introduction, page 47-43
Deployment, page 47-44
Configuring RA Guard, page 47-45
Examples, page 47-45
Usage Guidelines, page 47-46

Introduction

When deploying IPv6 networks, routers are configured to use IPv6 Router Advertisements to convey
configuration information to hosts onlink. Router Advertisement is a critical part of the
autoconfiguration process. The conveyed information includes the implied default router address
Frame
Routing function
VLAN 10
Host A
(VLAN 10)
Packet
94094
Catalyst 4500 series switch
VLAN 20
Host B
(VLAN 20)
VLAN 10
map
Input
PACL
Input
router
ACL
Output
router
ACL VLAN 20
map