l2 switch operation - security ACL

hi dears,

right now I am preparing for switch exam and concrete I don't know how is possible that L2 switch may to performed some checking (security ACLs) on layer3 and layer4? How is this possible omg, that's L2 switch...

from switch book:
security ACLs—Access control lists (ACL) can be used to identify frames according to their MAC addresses, protocol types (for non-IP frames), IP addresses, protocols, and Layer 4 port numbers. The ternary content-addressable memory (TCAM) contains ACLs in a compiled form so that a decision can be made on whether to for-ward a frame in a single table lookup.

Can someone explain me how it's possible.

IMPORTANT:I am not talking about MLS I am talking about pure L2 switch.

THANKS for replies.



