| 7.3 | Flow Masks | ||
| 7.3.4 | Input access lists and flow masks |
| As with output access lists, placing
an input access list on an MLS-enabled interface purges the MLS
cache of all existing flows for that interface. However, because the
default behavior for the input access list is to examine and route
all incoming packets, all subsequent packets in the flow between
Hosts A and B are routed.
Routers configured with Cisco IOS Release 11.3 or later will not automatically support input access lists on an interface configured for MLS. If an interface is configured with an input access list, all packets for a flow that are destined for that interface go through the router. The exception is the Catalyst 6000 Series Switch with MSFC or MSFC II that automatically supports MLS with access-lists. Even if the router allows that flow, the flow is not Layer 3 switched. To enable multilayer switching to cooperate with input access lists, enter the following command in global configuration mode.
The example in the Figure shows that input access control lists (ACLs) on the MLS-RP are configured to work in a multilayer-switching environment. To remove support for input access lists in a multilayer-switching environment, enter the no mls rp ip input-acl command in global configuration mode. |