Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

Multi layer switching and ACL's

Can anyone direct me to documentation on MLS and using both inbound and outbound acl's.

Any known problems utilizing both inbound and outbound acl with MLS?

thank you!

4 REPLIES
Cisco Employee

Re: Multi layer switching and ACL's

I'm assuming you are asking this for a CAT6k. ACLs are implemented in hardware and should not have performance issues. See if the following document helps

http://www.cisco.com/warp/customer/cc/pd/si/casi/ca6000/tech/65acl_wp.pdf

New Member

Re: Multi layer switching and ACL's

Thank you for the links

New Member

Re: Multi layer switching and ACL's

Hi Prkrishn

What If I wanted to apply MLS to a 5500 with NFFC 2...I read somewhere that there wasa possible security risk with the extended ACL's ...

eg if snmp is allowed but icmp is not ... and the first flow between two workstns is snmp, then an mls entry is made ... but if the second flow is icmp and that is blocked by the acl ... would the switch forward it? Is deny traffic "always" handled by the MLS-RP?

the article I read also mentioned that this was a Cisco bug and it was solved with the 6000 series using a PFC..

Any comments on this would be highly appreciated

129
Views
0
Helpful
4
Replies
CreatePlease login to create content