![](/images/new-backgrounds/1170316/17031697x1.webp)
Chapter 1 Controlling CSS Access
| Controlling CSS Network Traffic Through Access Control Lists |
|
Table | ||
|
|
|
Variables and |
|
|
Options | Parameters | |
|
|
|
prefer | Prefer the specified service as the traffic destination over | |
service_name | other services. To define more than one preferred service, | |
| separate each service with a comma (,). You can define a | |
| maximum of two services. | |
| You cannot configure services learned through an | |
| Application Peering Protocol (APP) session as preferred | |
| services. A remote service learned through APP is of the | |
| form | |
| the show service summary screen. When configuring an | |
| ACL clause, you cannot use this service as a preferred | |
| service. If you save this clause in the | |
| reboot the CSS, a startup error occurs because this service | |
| has not been learned through APP at this point. For | |
| example: | |
| clause 10 permit any any destination any prefer | |
| ||
| Note ACLs configured with a preferred service take | |
| precedence over stickiness. | |
| If you specify both a source group and a preferred | |
| service in a clause, you must specify the source | |
| group before you specify the preferred service | |
| within the clause. | |
|
|
|
After you create clauses for an ACL, you can apply the ACL to a circuit. For more information, see the “Applying an ACL to a Circuit or DNS Queries” section.
Adding a Clause When ACLs are Globally Enabled
If you are adding a new clause to an applied ACL when ACLs are globally enabled on the CSS, you must reapply the ACL to the circuit using the apply circuit command for the clause to take effect.
|
| Cisco Content Services Switch Security Configuration Guide |
|
|
|
|
| ||
|
|
| ||
|
|
|