Contents
viii
Catalyst 6500 Series Switch and Cisco 7600 Series Router Firewall Services Module Configuration Guide
OL-6392-01
Global Address Guidelines 9-12
DNS and NAT 9-13
Setting Connection Limits in the NAT Configuration 9-16
Using Dynamic NAT and PAT 9-16
Dynamic NAT and PAT Implementation 9-17
Configuring NAT or PAT 9-23
Using Static NAT 9-26
Using Static PAT 9-27
Bypassing NAT 9-29
Configuring Identity NAT 9-29
Configuring Static Identity NAT 9-30
Configuring NAT Exemption 9-31
NAT Examples 9-32
Overlapping Networks 9-33
Redirecting Ports 9-34
CHAPTER
10 Controlling Network Access with Access Control Lists 10-1
Access Control List Overview 10-1
Access Control List Types and Uses 10-2
Access Control List Type Overview 10-2
Controlling Network Access for IP Traffic (Extended) 10-2
Identifying Traffic for AAA rules (Extended) 10-3
Controlling Network Access for IP Traffic for a Given User (Extended) 10-4
Identifying Addresses for Policy NAT and NAT Exemption (Extended) 10-4
VPN Management Access (Extended) 10-5
Controlling Network Access for Non-IP Traffic (EtherType) 10-5
Redistributing OSPF Routes (Standard) 10-6
Access Control List Guidelines 10-6
Access Control Entry Order 10-6
Access Control List Implicit Deny 10-6
Access Control List Commit 10-6
Maximum Number of ACEs 10-7
IP Addresses Used for Access Control Lists When You Use NAT 10-7
Inbound and Outbound Access Control Lists 10-10
Access Control List Override 10-13
Adding an Extended Access Control List 10-13
Adding an EtherType Access Control List 10-16
Adding a Standard Access Control List 10-17