Chapter 23
Configuring Network Security
When defining a VLAN access map, note the following syntax information:
•
•
•
•
•
See the
Configuring a Match Clause in a VLAN Access Map Sequence
To configure a match clause in a VLAN access map sequence, perform this task:
Command
Router(config-access-map)# match {ip address {1-199 |
1300-2699 | acl_name} | ipx address {800-999 |
acl_name}| mac address acl_name}
Router(config-access-map)# no match {ip address
{1-199 | 1300-2699 | acl_name} | ipx address {800-999
| acl_name}| mac address acl_name}
When configuring a match clause in a VLAN access map sequence, note the following syntax
information:
•
•
•
•
•
See the
78-14064-04
To insert or modify an entry, specify the map sequence number.
If you do not specify the map sequence number, a number is automatically assigned.
You can specify only one match clause and one action clause per map sequence.
Use the no keyword with a sequence number to remove a map sequence.
Use the no keyword without a sequence number to remove the map.
"VLAN Access Map Configuration and Verification Examples" section on page
You can select one or more ACLs.
VACLs attached to WAN interfaces support only standard and extended Cisco IOS IP ACLs.
Use the no keyword to remove a match clause or specified ACLs in the clause.
For information about named MAC-Layer ACLs, refer to the
Access Lists (Optional)" section on page
For information about Cisco IOS ACLs, refer to the Cisco IOS Security Configuration Guide,
Release 12.1, "Traffic Filtering and Firewalls," "Access Control Lists: Overview and Guidelines,"
at this URL:
http://www.cisco.com/univercd/cc/td/doc/product/software/ios121/121cgcr/secur_c/scprt3/index.htm
"VLAN Access Map Configuration and Verification Examples" section on page
Purpose
Configures the match clause in a VLAN access map sequence.
Deletes the match clause in a VLAN access map sequence.
32-39.
Cisco 7600 Series Router Cisco IOS Software Configuration Guide—12.1E
Configuring VLAN ACLs
23-15.
"Configuring MAC-Layer Named
23-15.
23-13