Cisco WS-X6708-10G-3CXL= - 10 Gigabit Ethernet Module Manual de usuario Pagina 61

  • Descarga
  • Añadir a mis manuales
  • Imprimir
  • Pagina
    / 62
  • Tabla de contenidos
  • MARCADORES
  • Valorado. / 5. Basado en revisión del cliente
Vista de pagina 60
White Paper
© 2010 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public Inf ormation. Page 61 of 62
Entries: 22 32746 0 144 LOU: 0 128 0
ANDOR: 0 16 0
ORAND: 0 16 0
ADJ: 3 2045 0
VLAN ACLs
VACLs refers to all ACLs that are applied to Layer 2 VLANs directly and affect both traffic that is switched within the
VLAN for which the VACL is applied and traffic that is routed through the VLAN. VACLs are bidirectional.
In a Cisco Virtual Switching System environment, VACLs do not change significantly because they can be applied
across VLANs that are local to a particular virtual switch as well as across the entire Cisco Virtual Switching System.
Global TCAM show commands have also been extended to account for the switch keyword.
Port-Based ACLs
PACLs refers to those ACLs that are applied directly to a physical port that is also configured as a Layer 2 switchport.
Note that when an IP address is applied to such an interface, the ACL becomes a RACL. PACLs are directional by
nature, and only ingress PACLs are supported.
For software releases prior to 12.2(33)SXI4 there are some changes made to the way PACLs are applied in a Cisco
Virtual Switching System environment. They relate to the current software restriction that does not allow the system
to consecutively address more than 2000 ports from a Layer 2 ACL indexing perspective. This limitation implies that
PACLs cannot be applied to physical orphan portsports that exist on a single chassis only. You can apply PACLs
only on Layer 2 Cisco EtherChannel links or multichassis Cisco EtherChannel links. This behavior is evidenced by
the CLI not being available on physical Layer 2 interfaces:
vss(config)#int gig 1/5/2
vss(config-if)#switchport
vss(config-if)#ip ?
Interface IP configuration subcommands:
admission Apply Network Admission Control
arp Configure ARP features
auth-proxy Apply authenticaton proxy
<…snip>
vss(config)#int port-channel 102
vss(config-if)#switchport
vss(config-if)#ip ?
Interface IP configuration subcommands:
access-group Specify access control for packets
admission Apply Network Admission Control
arp Configure ARP features
auth-proxy Apply authenticaton proxy
<…snip>
PACLs on physical layer 2 interfaces are supported in VSS beginning in the 12.2(33)SXI4 software.
Vista de pagina 60
1 2 ... 56 57 58 59 60 61 62

Comentarios a estos manuales

Sin comentarios