Administrator Guide

Table Of Contents
632 Access Control Lists
MAC access list actions include CoS queue assignment, logging, mirroring,
redirection to another port, and logging, as well as the usual permit and deny
actions. It is possible to configure MAC access groups in conjunction with IP
access groups on the same interface. MAC ACLs can be configured on a
VLAN interface as well as a physical interface or port channel.
What Are IP ACLs?
IP ACLs contain filters for layers 3 and 4 on IPv4 or IPv6 traffic.
Each IP ACL is a set of up to 100 rules applied to inbound or outbound
traffic. IP ACLs support logging, redirect, mirroring, and drop. The following
fields may be specified in the permit or deny rules.
Destination IP with wildcard mask
Destination layer-4 port
Every protocol or a specific protocol
•IP DSCP
IP precedence
•IP TOS
•TCP flags
Source IP with wildcard mask
Source layer-4 port, with eq, ne, gt, and lt operators and ranges
(IP/TCP/UDP packets only)
Destination layer-4 port, with eq, ne, gt, and lt operators and ranges
(TCP/UDP packets only)
IP access lists may be configured on physical interfaces and port channels as
well as VLANs.
ACL Actions
The following actions are available for ingress ACLs. Not all actions are
available for all types of ACLs. Refer to "ACL Limitations " on page 635 for
more details.
CoS queue assignmentassign the matching packet to the specific CoS
queue. This action does not rewrite any fields in the packet.