cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
532
Views
0
Helpful
4
Replies

VACL vs Access-Group

Jason Fraioli
Level 3
Level 3

I was doing some lab scenarios this afternoon with a couple of layer 3 switches and realized that I can build an access list and apply it to a vlan interface. Since that is the case, what is the logic behind using VACL's?

4 Replies 4

Istvan_Rabai
Level 7
Level 7

Hi Jason,

VACL's can also be used for bridged traffic in a VLAN.

The following link may give you a good explanation on the relationship of IOS acl's and vacl's, on the sequence of processing them for routed and bridged traffic, etc.

http://www.cisco.com/en/US/docs/switches/lan/catalyst6500/ios/12.2SXF/native/configuration/guide/vacl.html

Cheers:

Istvan

Edison Ortiz
Hall of Fame
Hall of Fame

VACLs are processed in hardware in Catalyst switches hence they don't take any CPU cycles. You can run multiple VACLs without affecting the switch utilization.

HTH,

__

Edison.

Edison,

Aren't the normal L3 ACLs also compiled in TCAMs and processed in hardware?

Narayan

I was referring mainly on how is done in Cat6k where you have a SP (Switch Processor) and RP (Route Processor). SP handles the VACL while RP handles the L3 ACLs.

__

Edison.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card