Policies and Filters

Default Filter Actions

By default, no policies or filters are defined on the routing switches and switch. The following table lists the default action when no policy or filter is configured and the default action after you configure a policy or filter. For some types of policies and filters, the default action changes once you configure a policy or filter, regardless of the policy or filter’s contents.

Table C.2: Default Policy and Filter Actions

 

Policy or Filter Type

Default action when no policies

Default action after a policy or

 

 

 

or filters are configured

filter is configured

 

 

 

 

 

QoS policy

Queue all packets in normal or 0

Queue all packets in normal or 0

 

 

 

priority queue

priority queue unless explicitly

 

 

 

 

configured for a higher queue

 

 

 

 

 

Access policy (see Forwarding

See Forwarding filters

See Forwarding filters

 

filters)

 

 

 

 

 

 

 

 

Forwarding filters

Permit (forward) all packets

Deny (drop) all packets

 

MAC forwarding filters

 

Note: The default action for

 

IP forwarding filters

 

AppleTalk zone and network filters

 

 

is always permit. To deny all but

 

 

(same as IP access

 

 

 

 

specific zones, create permit filters

 

 

policy)

 

 

 

 

for those zones, then create a deny

 

 

 

 

 

IPX forwarding filters

 

filter and use the “additional zones”

 

TCP/UDP forwarding

 

value with the filter.

 

 

 

 

 

filters

 

 

 

 

 

 

 

Address-lock filter

Permit (forward) all packets

Permit only those packets whose

 

 

 

 

source MAC addresses have been

 

 

 

 

learned on the port; drop all others

 

 

 

 

 

Route filters

Permit (learn and advertise) all

Deny (do not learn or advertise) all

 

IP/RIP route filters

routes or services

routes or services

 

 

 

 

IP/RIP neighbor filters

 

 

 

• IPX RIP route filters

 

 

 

• IPX SAP service filters

 

 

 

AppleTalk zone and

 

 

 

 

network filters

 

 

 

BGP4 address filters

 

 

 

• BGP4 AS-path filters

 

 

 

BGP4 community

 

 

 

 

filters

 

 

 

 

 

 

 

Route redistribution filter

Do not redistribute routes

Do not redistribute routes unless

 

IP/RIP

 

explicitly redistributed by filter

 

 

 

 

OSPF

 

Note: For IP/RIP and OSPF, you

 

 

must explicitly enable redistribution.

 

 

 

 

 

BGP4

 

Redistribution is enabled by default

 

 

 

 

in BGP4.

 

 

 

 

 

Layer 2 broadcast and multicast

Allow outbound broadcasts and

Drop outbound broadcasts or

 

filters

 

multicasts on the specified ports

multicasts on the specified ports

 

 

 

 

 

 

 

 

 

 

C - 3