Prev | Current Page 90 | Next

Yusuf Bhaiji

"Network Security Technologies and Solutions"

As discussed earlier, timebased
ACLs were not initially supported on the line cards in the Cisco 7500 series. If an interface on a 7500 line
card was configured with a time-based ACL, the packets switched into the interface were not "distributed
switched" through the line card. Instead, they were forwarded to the route processor for processing and
therefore did not take advantage of the distributed switching capability. The distributed time-based ACLs
feature allows packets destined for an interface that are configured with time-based ACLs to be "distributedswitched"
through the line card.
Distributed time-based ACLs leverage the performance benefits of distributed switching and the flexibility
provided by time-based ACLs. The software clock must remain synchronized between the Route Processor (RP)
and the line card for the distributed time-based ACL to function properly.
Configuring Distributed Time-Based ACLs
Because this feature is enabled automatically when the normal time-range ACL is configured on a line card
interface, there is no command syntax to enable this feature. The command syntax is the same as for the timebased
ACL. The function is only a software code integration in the IOS; no additional commands are required.


Pages:
78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102