Chapter 31
Configuring Network Security with ACLs
Examples of Router ACLs and VLAN Maps Applied to VLANs
This section gives examples of applying router ACLs and VLAN maps to a VLAN for switched, routed,
and multicast packets. Although the following illustrations show packets being forwarded to their
destination, each time the packet's path crosses a line indicating a VLAN map or an ACL, it is also
possible that the packet might be dropped, rather than forwarded.
ACLs and Switched Packets
Figure 31-6
within the VLAN without being routed or forwarded are only subject to the VLAN map of the input
VLAN.
Figure 31-6
Host A
(VLAN 10)
ACLs and Routed Packets
Figure 31-7
in this order:
1.
2.
3.
4.
OL-9639-07
shows how an ACL is applied on packets that are switched within a VLAN. Packets switched
Applying ACLs on Switched Packets
VLAN 10
map
Frame
Host C
(VLAN 10)
VLAN 10
shows how ACLs are applied on routed packets. For routed packets, the ACLs are applied
VLAN map for input VLAN
Input router ACL
Output router ACL
VLAN map for output VLAN
Input
Output
router
router
ACL
ACL
Routing function or
fallback bridge
Packet
Cisco ME 3400 Ethernet Access Switch Software Configuration Guide
Using VLAN Maps with Router ACLs
VLAN 20
map
VLAN 20
31-37