EasyManuals Logo

Cisco Catalyst 4500 Series Software Configuration Guide

Cisco Catalyst 4500 Series
2086 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #1630 background imageLoading...
Page #1630 background image
62-6
Catalyst 4500 Series Switch, Cisco IOS Software Configuration Guide - Cisco IOS XE 3.9.xE and IOS 15.2(5)Ex
Chapter 62 Configuring Network Security with ACLs
Hardware and Software ACL Support
Figure 62-2 Using VLAN Maps to Control Traffic
Hardware and Software ACL Support
This section describes how to determine whether ACLs are processed in hardware or in software:
• Flows that match a deny statement in standard and extended ACLs are dropped in hardware if ICMP
unreachable messages are disabled.
• Flows that match a permit statement in standard ACLs are processed in hardware.
• The following ACL types are not supported in software:
–
Standard Xerox Network Systems (XNS) Protocol access list
–
Extended XNS access list
–
DECnet access list
–
Protocol type-code access list
–
Standard Internet Packet Exchange (IPX) access list
–
Extended IPX access list
Note Packets that require logging are processed in software. A copy of the packets is sent to the CPU for
logging while the actual packets are forwarded in hardware so that non-logged packet processing is not
impacted.
By default, the Catalyst 4500 Series Switch sends ICMP unreachable messages when a packet is denied
by an access list; these packets are not dropped in hardware but are forwarded to the switch so that it can
generate the ICMP unreachable message.
To drop access list denied packets in hardware on the input interface, you must disable ICMP
unreachable messages using the no ip unreachables interface configuration command. The
ip unreachables command is enabled by default.
Note Cisco IOS Release 12.2(40)SG does not support disabling IP unreachables on interfaces routing IPv6
traffic.
Note If you set the no ip unreachable command on all Layer 3 interfaces, output ACL denied packets do not
come to the CPU.
Si
Host B
(VLAN 10)
Host A
(VLAN 10)
94153
= VLAN map denying specific type
of traffic from Host A
= Packet
Catalyst 4500 series switch

Table of Contents

Other manuals for Cisco Catalyst 4500 Series

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the Cisco Catalyst 4500 Series and is the answer not in the manual?

Cisco Catalyst 4500 Series Specifications

General IconGeneral
SeriesCatalyst 4500 Series
CategorySwitch
Layer SupportLayer 2, Layer 3
Form FactorModular chassis
StackableNo
Chassis Slots3, 6, 7, 10
Power Supply OptionsAC, DC
RedundancyPower supply, Supervisor engine
Network ManagementCisco IOS Software CLI, SNMP, Cisco Prime Infrastructure
FeaturesSecurity, QoS
Port DensityUp to 384 ports per chassis
Security Features802.1X, ACLs, DHCP Snooping, Dynamic ARP Inspection, IP Source Guard
Supervisor Engine8-E

Related product manuals