37-40

Catalyst 3750-X and 3560-X Switch Software Configuration Guide
OL-21521-01
Chapter 37 Configuring Network Security with ACLs
Using VLAN Maps with Router ACLs
Figure 37-7 Applying ACLs on Bridged Packets
ACLs and Routed Packets

Figure 37-8 shows how ACLs are applied on routed packets. The ACLs are applied in this order:

1. VLAN map for input VLAN
2. Input router ACL
3. Output router ACL
4. VLAN map for output VLAN
Figure 37-8 Applying ACLs on Routed Packets
Frame
Fallback bridge
VLAN 10
Host A
(VLAN 10)
Packet
101358
VLAN 20
Host B
(VLAN 20)
VLAN 10
map VLAN 20
map
Frame
Routing function
VLAN 10
Host A
(VLAN 10)
Packet
101359
VLAN 20
Host B
(VLAN 20)
VLAN 10
map
Input
router
ACL
Output
router
ACL VLAN 20
map