Users Guide

Table Of Contents
706 Access Control Lists
MAC access list actions include CoS queue assignment, logging, mirroring,
redirection to another port, and logging, as well as the usual permit and deny
actions. It is possible to configure MAC access groups in conjunction with IP
access groups on the same interface. MAC ACLs can be configured on a
VLAN interface as well as a physical interface or port channel.
What Are IP ACLs?
IP ACLs contain filters for layers 3 and 4 on IPv4 or IPv6 traffic.
Each IP ACL is a set of up to the maximum supported rules applied to
inbound or outbound traffic. See Table 19-2. IP ACLs support logging,
redirect, mirroring, and drop. The following fields may be specified in the
permit or deny rules.
Destination IP with wildcard mask
Every protocol or a specific protocol
IP DSCP
IP precedence
IP TOS
TCP flags
Source IP with wildcard mask
Source Layer-4 port, with eq, ne, gt, and lt operators and ranges
(IP/TCP/UDP packets only)
Destination Layer-4 port, with eq, ne, gt, and lt operators and ranges
(TCP/UDP packets only)
IP access lists may be configured on physical interfaces and port channels as
well as VLANs.
ACL Actions
The following actions are available for ingress ACLs. Not all actions are
available for all types of ACLs. Refer to "ACL Limitations" on page 709 for
more details.
CoS queue assignment assign the matching packet to the specific CoS
queue. This action does not rewrite any fields in the packet.