EasyManuals Logo
Home>Cisco>Network Router>7609

Cisco 7609 User Manual

Cisco 7609
572 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #339 background imageLoading...
Page #339 background image
23-17
Cisco 7600 Series Router Cisco IOS Software Configuration Guide—12.1E
78-14064-04
Chapter 23 Configuring Network Security
Configuring VLAN ACLs
When configuring a capture port, note the following syntax information:
With Release 12.1(13)E and later releases, you can configure any port as a capture port. With earlier
releases, only the Gigabit Ethernet monitor port on the IDS module can be configured as a capture
port.
When configuring a capture port with Release 12.1(13)E and later releases, note the following
syntax information:
The vlan_list parameter can be a single VLAN ID or a comma-separated list of VLAN IDs or
VLAN ID ranges (vlan_IDvlan_ID).
To encapsulate captured traffic, configure the capture port with the switchport trunk
encapsulation command (see the Configuring a Layer 2 Switching Port as a Trunk section on
page 7-8) before you enter the switchport capture command.
To not encapsulate captured traffic, configure the capture port with the switchport mode access
command (see the Configuring a LAN Interface as a Layer 2 Access Port section on
page 7-14) before you enter the switchport capture command.
The capture port supports only egress traffic. No traffic can enter the router through a
capture port.
This example shows how to configure a Fast Ethernet interface 5/1 as a capture port:
Router(config)# interface gigabitEthernet 5/1
Router(config-if)# switchport capture
Router(config-if)# end
This example shows how to display VLAN access map information:
Router# show vlan access-map mordred
Vlan access-map "mordred" 10
match: ip address net_10
action: forward capture
Router#
This example shows how to display mappings between VACLs and VLANs. For each VACL map, there
is information about the VLANs that the map is configured on and the VLANs that the map is active on.
A VACL is not active if the VLAN does not have an interface.
Router# show vlan filter
VLAN Map mordred:
Configured on VLANs: 2,4-6
Active on VLANs: 2,4-6
Router#
Configuring VACL Logging
When you configure VACL logging, IP packets that are denied generate log messages in these situations:
When the first matching packet is received
For any matching packets received during the last 5-minute interval
If the threshold is reached before the 5-minute interval
Log messages are generated on a per-flow basis. A flow is defined as packets with the same IP addresses and
Layer 4 (UDP or TCP) port numbers.
When a log message is generated, the timer and packet count is reset.

Table of Contents

Other manuals for Cisco 7609

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the Cisco 7609 and is the answer not in the manual?

Cisco 7609 Specifications

General IconGeneral
BrandCisco
Model7609
CategoryNetwork Router
LanguageEnglish

Related product manuals