
642 -531
Leading the way in IT testing and certification tools, www.testking.com
- 32 -
B. Map the VLAN access map to a VLAN.
C. Use commit to save the VACL configuration.
D. Assign ports to receive capture traffic.
E. Crate VACL using the set security acl command.
ANSWER: B, D
Explanation:
The tasks to capture traffic using VLAN Access Control Lists (VACLs) on a Catalyst 6500
switch running IOS are as follows:
1) Configure ACLs to define interesting traffic.
2) Define a VLAN access map
3) Configure the match clause in the VLAN access map using ACLs
4) Configure the action clause in the VLAN access map using the capture option.
5) Apply the VLAN access-map to the specified VLANs
6) Select an interface.
7) Enable the capture function on the interface.
Cisco Courseware 5-38
QUESTION NO: 14
What is a primary reason for using the mls ip ids command to capture traffic instead of
VACLs?
A. higher performance due to hardware-based multilayer switching
B. CBAC is configured on the same VLAN
C. Switch is running Catalyst OS; VACLs are only supported in IOS
D. Destination capture port is an IDSM; VACLs do not support IDSM
E. mls ip ids offers more granularity for traffic capture than VACLs
ANSWER: B
You cannot apply VACLs to the same VLAN
in which you have applied an IP inspect rule for
the Cisco IDS Firewall.
(IP inspect rule is a CBAC feature -> mls ip ids
can be used instead of VACLs to solve this
problem)
Cisco Courseware 5-45, 5-48
QUESTION NO: 15
Network topology exhibit:
Komentarze do niniejszej Instrukcji