The VACL's are used to filter traffic within a vlan and it has no direction as opposed to RACL's. The match can be either on mac acl or ip acl. The RACL's are used on routed ports same as in case of routers.
Here is a link describing how to configure it and gives some information how it works:
Port ACLs access-control traffic entering a Layer 2 interface. The switch does not support port ACLs in the outbound direction (on 3550). You can apply only one IP access list and one MAC access list to a Layer 2 interface.
We are pleased to announce availability of Beta software for 16.6.3. 16.6.3 will be the second rebuild on the 16.6 release train targeted towards Catalyst 9500/9400/9300/3850/3650 switching platforms. We are looking for early feedback from custome...