Port ACL (PACL) Restrictions and Design Considerations
Port Access Control Lists (PACLs) are ACLs that can be applied to Layer 2 switchports. However, they have certain restrictions compared to their Layer 3 counterparts.
These limitations are due to switch architecture and hardware considerations and include:
- No Outbound (Egress) Filtering:
- Control Plane Traffic:
- PACLs cannot filter Layer 2 control protocols (CDP, VTP, DTP)
- Control plane and data plane filtering must remain separate
- Control Plane Policing (CoPP) should be used instead for control traffic
- Protocol Support:
PACL limitations on Layer 2 are primarily driven by switch ASIC architecture, control plane separation requirements, and platform-specific hardware capabilities.
Links
https://networklessons.com/cisco/ccie-routing-switching-written/ipv6-pacl-port-acl