Installation guide

4-68
Device Manager Guide, Cisco ACE 4700 Series Application Control Engine Appliance
OL-26645-02
Chapter 4 Configuring Virtual Contexts
Configuring Security with ACLs
BPDU—Specifies Bridge Protocol Data Units. The ACE receives trunk port (Cisco proprietary)
BPDUs because ACE ports are trunk ports. Trunk BPDUs have VLAN information inside the
payload, so the ACE modifies the payload with the outgoing VLAN if you allow BPDUs. If you
configure redundancy, you must allow BPDUs on both interfaces with an EtherType ACL to avoid
bridging loops. For for information about configuring redundancy, see the “Configuring High
Availability” section on page 11-1.
IPv6—Specifies Internet Protocol version 6.
MPLS—Specifies Multi Protocol Label Switching. The MPLS selection applies to both MPLS
unicast and MPLS multicast traffic. If you allow MPLS, ensure that Label Distribution Protocol
(LDP) and Tag Distribution Protocol (TDP) TCP connections are established through the ACE by
configuring both MPLS routers connected to the ACE to use the IP address on the ACE interface as
the router-id for LDP or TDP sessions. LDP and TDP allow MPLS routers to negotiate the labels
(addresses) used to forward packets.
Step 6 Click Add To Table and add one or more ACL entries if required repeating Step 4 and Step 5 as needed.
Step 7 Associate any VLAN interface to this ACL if required and do one of the following:
Click Deploy to immediately deploy this configuration.
Click Cancel to exit without saving your entries and to return to the ACL Summary table.
Related Topics
Configuring Security with ACLs, page 4-58
Creating ACLs, page 4-59
Setting Extended ACL Attributes, page 4-61
Resequencing Extended ACLs, page 4-66
Editing or Deleting ACLs, page 4-69
Viewing All ACLs by Context
Use this procedure to view all access control lists that have been configured.
Procedure
Step 1 Choose Config > Virtual Contexts.
The All Virtual Contexts table appears.
Step 2 Choose the virtual context with the ACLs you want to view, and then select Security > ACLs.
The ACLs table appears, listing the existing ACLs with their name, their type (Extended or EtherType),
and any comments.
Related Topics
Configuring Virtual Context Expert Options, page 4-79
Creating ACLs, page 4-59
Setting EtherType ACL Attributes, page 4-67