How Hardware-based ACLs Work

When you bind an ACL to inbound or outbound traffic on an interface or VLAN, the device programs the Layer 4 CAM with the ACL. Permit and deny rules are programmed. Most ACL rules require one Layer 4 CAM entry. However, ACL rules that match on more than one TCP or UDP application port may require several CAM entries. The Layer 4 CAM entries for ACLs do not age out. They remain in the CAM until you remove the ACL:

  • If a packet received on the interface or VLAN matches an ACL rule in the Layer 4 CAM, the device permits or denies the packet according to the ACL.
  • If a packet does not match an ACL rule, the packet is dropped because the default action on an interface or VLAN that has ACLs is to deny the packet.