28-38

Cisco ME 3400 EthernetAccess Switch SoftwareConfiguration Guide
78-17058-01
Chapter28 Configuring Network Security with ACLs
Using VLAN Maps with Router ACLs
Figure28-6 Applying ACLs on Switched Packets
ACLs and Routed Packets

Figure 28-7 shows how ACLs are applied on routed packets. For routed packets, the ACLs are applied

in this order:

1. VLAN map for input VLAN
2. Input router ACL
3. Output router ACL
4. VLAN map for output VLAN
Figure 28-7 Applying ACLs on Routed Packets
VLAN 10
map
Frame
Input
router
ACL
Output
router
ACL
Routing function or
fallback bridge
VLAN 10 VLAN 20
Host C
(VLAN 10)
Host A
(VLAN 10)
VLAN 20
map
Packet
101357
Frame
Routing function
VLAN 10
Host A
(VLAN 10)
Packet
101359
VLAN 20
Host B
(VLAN 20)
VLAN 10
map
Input
router
ACL
Output
router
ACL VLAN 20
map