CHAPTER 9
Implementing of Layer 2 Access Lists
An Ethernet services access control list (ACL) consists of one or more access control entries (ACE) that
collectively define the Layer 2 network traffic profile. This profile can then be referenced by Cisco IOS XR
software features. Each Ethernet services ACL includes an action element (permit or deny) based on criteria
such as source and destination address, Class of Service (CoS), or VLAN ID.
This module describes tasks required to implement Ethernet services access lists on your Cisco ASR 9000
Series Aggregation Services Router.
For a complete description of the Ethernet services access list commands listed in this module, refer to the
Ethernet Services (Layer 2) Access List Commands on Cisco ASR 9000 Series Routers module in the Cisco
ASR 9000 Series Aggregation Services Router IP Addresses and Services Command Reference publication.
To locate documentation of other commands that appear in this chapter, use the command reference master
index, or search online.
Note
Feature History for Implementing Ethernet Services Access Lists on Cisco ASR 9000 Series Routers
ModificationRelease
This feature was introduced on Cisco ASR 9000 Series
Routers.
Release 3.7.2
• Prerequisites for Implementing Layer 2 Access Lists, on page 463
• Information About Implementing Layer 2 Access Lists, on page 464
• How to Implement Layer 2 Access Lists, on page 466
• Configuration Examples for Implementing Layer 2 Access Lists, on page 471
Prerequisites for Implementing Layer 2 Access Lists
This prerequisite applies to implement access lists and prefix lists:
You must be in a user group associated with a task group that includes the proper task IDs. The command
reference guides include the task IDs required for each command.
If you suspect user group assignment is preventing you from using a command, contact your AAA administrator
for assistance.
L2VPN and Ethernet Services Configuration Guide for Cisco ASR 9000 Series Routers, IOS XR Release 6.3.x
463