Working with VACL

VLAN-based ACLs made their introduction on LAN switches some time after RACLs. VACLs provide the capability to filter traffic between hosts located in the same VLAN. They apply to IP and non-IP traffic alike. For example, using VACLs, it is possible to permit or deny traffic based on its source or destination MAC address. Naturally, IP addresses, User Datagram Protocol (UDP), and TCP ports can also be used as a selection criteria. Contrary to a VACL, a RACL cannot match intra-VLAN traffic because traffic between hosts inside a common VLAN does not transit through a routed interface at all. Figure 16-2 shows the VACL concept.

Figure 16-2 VACL Example

_

1

—1

11 1

-

H

1 VACL 1 Switch

VLAN 10

VACL Applied to Traffic Bridged Within a VLAN

VACL Applied to Traffic Bridged Within a VLAN

NOTE VACLs essentially follow the same format as RACLs; it's just their operation principle that differs.

VACLs are convenient to provide access control for an entire VLAN in one shot. For example, if you want to prevent all users in VLAN 20 from surfing the Internet, apply a VACL on VLAN 20 to deny all sources from communicating to any destination using TCP port 80. Notice that we are not applying the VACL to specific ports in VLAN 20, but rather to traffic entering and leaving the switch through VLAN 20. Although VACLs and RACLs might appear to be closely related, the key difference between them is that a RACL is unable to match traffic that is Layer 2 switched between two ports inside the same VLAN, while a VACL can.

Unlike RACLs, VACLs are directionless. That is, they match ingress and egress traffic to and from the VLAN. Figure 16-3 illustrates how they apply to traffic entering and exiting the VLAN.

Figure 16-3 VACLs Are Directionless

VACL Applied at Ingress VACL Applied at Egress sz

Switch

Packets Arriving on Layer 2 Interface Have the VACL Processed on Ingress and Egress

Packets Arriving on Layer 2 Interface Have the VACL Processed on Ingress and Egress

A VACL used in conjunction with the capture option is frequently used to send specific traffic from a VLAN to a network analyzer, as Figure 16-4 shows, for example. Thanks to the selective VACL match syntax, only a fraction of the entire traffic in transit through the VLAN is sent to the analyzer.

Figure 16-4 VACL Capture

Source

The VACL Capture Is Especially Useful for

Source

The VACL Capture Is Especially Useful for

Destination

Oftentimes, the number of port-mirroring sessions available per switch is limited. Therefore, a VACL capture presents an advantageous alternative to port mirroring. Furthermore, port mirroring unselectively copies all traffic from a port or VLAN to another, while a VACL capture offers more granularity (thanks to the ACL match).

It is possible to combine both RACLs and VACLs on a given VLAN, as Figure 16-5 shows. This combination gives you the flexibility to control both intra-VLAN bridged traffic and traffic routed outside of the VLAN.

Figure 16-5 Combining RACLs and VACLs

It Is Possible to Combine the Use of RACL and VACL at the Same Time for Layer 3 Switched Packets

Figure 16-5 Combining RACLs and VACLs

It Is Possible to Combine the Use of RACL and VACL at the Same Time for Layer 3 Switched Packets

Input VACL Output VACL

Continue reading here: Technology Behind Fast ACL Lookups

Was this article helpful?

+1 0