23-9
Catalyst 6500 Series Switch Cisco IOS Software Configuration Guide—Release 12.1 E
78-14099-04
Chapter 23 Configuring Network Security
Configuring VLAN ACLs
When you configure a VACL and apply it to a VLAN, all packets entering the VLAN are checked against
this VACL. If you apply a VACL to the VLAN and an ACL to a routed interface in the VLAN, a packet
coming in to the VLAN is first checked against the VACL and, if permitted, is then checked against the
input ACL before it is handled by the routed interface. When the packet is routed to another VLAN, it
is first checked against the output ACL applied to the routed interface and, if permitted, the VACL
configured for the destination VLAN is applied. If a VACL is configured for a packet type and a packet
of that type does not match the VACL, the default action is deny.
Note VACLs and CBAC cannot be configured on the same interface.
TCP Intercepts and Reflexive ACLs take precedence over a VACL action if these are configured on
the same interface.
IGMP packets are not checked against VACLs.
Bridged Packets
Figure 23-1 shows a VACL applied on bridged packets.
Figure 23-1 Applying VACLs on Bridged Packets
Catalyst 6500 Series Switch
with PFC
Host B
(VLAN 10)
Host A
(VLAN 10)
26961
VACL Bridged