Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

ovt Bronze
Bronze

IPSG compatibility with VACL on 3550

Hi!

It is well known that PACLs are not compatible with VACLs (PACL on an interface in vlan X overrides VACL for vlan X).

The question is: Is IP Source Guard, which is based on PACLs, compatible with VACLs?

Quick testing shows that traffic is checked by both VACL and IPSG. If I specify "action drop" then the traffic is dropped. If I clear DHCP binding table then the traffic is not flowing too. "show fm ..." commands indicate that both PACL and VACL are applied. The problem is that "show fm interface fa0/1" says about "conflicting VACL"...

Does this mean that either PACL or VACL is processed by the software???

220
Views
0
Helpful
0
Replies
CreatePlease to create content