This chapter describes how to integrate ACLs with network protocols and interfaces on the Cisco 8000 Series Router, including use in class maps, inline action modifications, bridge virtual interfaces, Layer 2 interfaces, ACL-based forwarding, and internal VRF-based forwarding.
This chapter contains the following sections:
IPv4 and IPv6 ACL in class map
This topic describes the enhanced Quality of Service (QoS) support for using IPv4 and IPv6 access control lists (ACLs) in class maps on the Cisco 8000 Series Router.
Inline ACL action modifications
This topic explains how supported Cisco 8000 Series Routers update ACL actions without repositioning hardware entries and describes update behavior, forwarding continuity, scope, restrictions, and verification.
ACLs on bridge virtual interfaces
This topic describes how access control lists (ACLs) on a Bridge Virtual Interface (BVI) filter traffic for a group of Layer 2 interfaces.
IPv4 and IPv6 ACLs in Layer 2
This topic describes how IPv4 and IPv6 access control lists (ACLs) operate on Layer 2 physical and bundle main interfaces on the Cisco 8000 Series Router to filter traffic at the data link layer.
ACL-based forwarding
This topic describes ACL-based forwarding (ABF) on the Cisco 8000 Series Router, which routes traffic through a specified next hop instead of the path computed by routing protocols.
Virtual Routing and Forwarding (VRF) redirect in ABF
This topic describes how ACL-based forwarding (ABF) supports Virtual Routing and Forwarding (VRF) redirect for IPv4 and IPv6 addresses on the Cisco 8000 Series Router.
ABF over BVI
This topic describes ACL-based forwarding (ABF) for IPv4 and IPv6 addresses on a Bridge Virtual Interface (BVI) on the Cisco 8000 Series Router.
Internal VRF-based forwarding
This topic describes how the internal VRF-based forwarding feature uses a forwarding-match access control entry (ACE) to redirect packets that do not match predefined access control entries to an internal VRF (iVRF) for deep inspection through GRE tunneling.