Contents
xxxviii
Software Configuration Guide—Release 15.0(2)SG
OL-23818-01
Dynamic ACLs 47-5
VLAN Maps 47-5
Hardware and Software ACL Support 47-6
TCAM Programming and ACLs for Supervisor Engine
II-Plus, Supervisor Engine IV, Supervisor Engine V, and Supervisor Engine V-10GE 47-7
TCAM Programming Algorithms 47-8
Changing the Programming Algorithm 47-9
Resizing the TCAM Regions 47-11
Troubleshooting High CPU Due to ACLs 47-12
Selecting Mode of Capturing Control Packets 47-13
Guidelines and Restrictions 47-14
Selecting Control Packet Capture 47-15
TCAM Programming and ACLs for Supervisor Engine 6-E and Supervisor Engine 6L-E 47-16
Layer 4 Operators in ACLs 47-16
Restrictions for Layer 4 Operations 47-16
Configuration Guidelines for Layer 4 Operations 47-17
How ACL Processing Impacts CPU 47-18
Configuring Unicast MAC Address Filtering 47-20
Configuring Named MAC Extended ACLs 47-20
Configuring EtherType Matching 47-22
Configuring Named IPv6 ACLs 47-23
Applying IPv6 ACLs to a Layer 3 Interface 47-24
Configuring VLAN Maps 47-24
VLAN Map Configuration Guidelines 47-25
Creating and Deleting VLAN Maps 47-26
Examples of ACLs and VLAN Maps 47-26
Applying a VLAN Map to a VLAN 47-29
Using VLAN Maps in Your Network 47-29
Denying Access to a Server on Another VLAN 47-31
Displaying VLAN Access Map Information 47-32
Using VLAN Maps with Router ACLs 47-32
Guidelines for Using Router ACLs and VLAN Maps on the Same VLAN 47-32
Examples of Router ACLs and VLAN Maps Applied to VLANs 47-33
ACLs and Switched Packets 47-33
ACLs and Routed Packets 47-34
Configuring PACLs 47-35
Creating a PACL 47-35
PACL Configuration Guidelines 47-36