ACLs and VLAN Maps

When does one use ACLs vs VLAN Maps to filter traffic between VLANs?

The 3750 Command Reference states: "There can be only one VLAN map per VLAN and it is applied as packets are received by a VLAN."

Does "received by a VLAN" mean a packet that the 3750 forwards from one SVI to another or does it mean a packet that comes into a gigabit ethernet port that's a member of the VLAN?

For access-groups, do the keywords IN and OUT always refer to physical ports (and never to SVIs or to the process of forwarding packets from one VLAN to another)?

read more and respond »

Posted 5 years ago by Bob Simon in Cisco Systems

Report misuse

Image for ACLs and VLAN Maps