Chapter 23
Configuring Network Security
is first checked against the output ACL applied to the routed interface and, if permitted, the VACL
configured for the destination VLAN is applied. If a VACL is configured for a packet type and a packet
of that type does not match the VACL, the default action is deny.
Note
•
•
•
Bridged Packets
Figure 23-1
Figure 23-1 Applying VACLs on Bridged Packets
Host A
(VLAN 10)
78-14064-04
VACLs and CBAC cannot be configured on the same interface.
TCP Intercepts and Reflexive ACLs take precedence over a VACL action if these are configured on
the same interface.
IGMP packets are not checked against VACLs.
shows a VACL applied on bridged packets.
VACL
Bridged
Catalyst 6500 Series Switch
with PFC
Cisco 7600 Series Router Cisco IOS Software Configuration Guide—12.1E
Configuring VLAN ACLs
Host B
(VLAN 10)
23-9