2-85
Catalyst 2950 and Catalyst 2955 Switch Command Reference
OL-10102-01
Chapter 2 Catalyst 2950 and 2955 Cisco IOS Commands
deny (MAC access-list configuration)
deny (MAC access-list configuration)
Use the deny MAC access-list configuration command to prevent Layer 2 traffic from being forwarded
if the conditions are matched. Use the no form of this command to remove a deny condition from the
MAC named access control list (ACL).
{permit | deny} {any | host src-MAC-addr} {any | host dst-MAC-addr} [aarp | amber | appletalk
| dec-spanning | decnet-iv | diagnostic | dsm | etype-6000 | etype-8042 | lat | lavc-sca |
mop-console | mop-dump | msdos | mumps | netbios | vines-echo |vines-ip | xns-idp]
no {permit | deny} {any | host src-MAC-addr} {any | host dst-MAC-addr} [aarp | amber |
appletalk | dec-spanning | decnet-iv | diagnostic | dsm | etype-6000 | etype-8042 | lat |
lavc-sca | mop-console | mop-dump | msdos | mumps | netbios | vines-echo |vines-ip |
xns-idp]
This command is available only if your switch is running the enhanced software image (EI).
Syntax Description any Keyword to deny any source or destination MAC address.
host src-MAC-addr Define a host MAC address. If the source address for a packet matches
the defined address, traffic from that address is denied. MAC
address-based subnets are not allowed.
host dst-MAC-addr Define a destination MAC address. If the destination address for a packet
matches the defined address, traffic to that address is denied. MAC
address-based subnets are not allowed.
aarp Select Ethertype AppleTalk Address Resolution Protocol that maps a
data-link address to a network address.
amber Select EtherType DEC-Amber.
appletalk Select EtherType AppleTalk/EtherTalk.
dec-spanning Select EtherType Digital Equipment Corporation (DEC) spanning tree.
decnet-iv Select EtherType DECnet Phase IV protocol.
diagnostic Select EtherType DEC-Diagnostic.
dsm Select EtherType DEC-DSM.
etype-6000 Select EtherType 0x6000.
etype-8042 Select EtherType 0x8042.
lat Select EtherType DEC-LAT.
lavc-sca Select EtherType DEC-LAVC-SCA.
mop-console Select EtherType DEC-MOP Remote Console.
mop-dump Select EtherType DEC-MOP Dump.
msdos Select EtherType DEC-MSDOS.
mumps Select EtherType DEC-MUMPS.
netbios Select EtherType DEC-Network Basic Input/Output System (NETBIOS).
vines-echo Select EtherType Virtual Integrated Network Service (VINES) Echo from
Banyan Systems.