Usage 
Information
The order option is relevant in the context of the Policy QoS feature only. For more 
information, refer to the “Quality of Service” chapter of the 
FTOS Configuration Guide
.
When you use the log option, the CP processor logs details about the packets that match. 
Depending on how many packets match the log entry and at what rate, the CP may become 
busy as it has to log these packets’ details.
The monitor option is relevant in the context of flow-based monitoring only. For more 
information, refer to 
Port Monitoring.
You cannot include IP, TCP, or UDP filters in an ACL configured with ARP filters.
NOTE: When ACL logging and byte counters are configured simultaneously, byte counters 
may display an incorrect value. Configure packet counters with logging instead.
permit ether-type
Configure a filter that allows traffic with specified types of Ethernet packets. This command is supported only on 12-port 
GE line cards with SFP optics. For specifications, refer to your line card documentation.
E-Series
Syntax
permit ether-type protocol-type-number {destination-mac-address 
mac-address-mask | any} vlan vlan-id {source-mac-address mac-
address-mask | any} [count [byte] | log] [order] [monitor]
To remove this filter, you have two choices:
• Use the no seq sequence-number command if you know the filter’s sequence 
number.
• Use the no permit ether-type protocol-type-number 
{destination-mac-address mac-address-mask | any} vlan 
vlan-id {source-mac-address mac-address-mask | any} 
command.
Parameters
protocol-type-
number
Enter a number from 600 to FFF as the specific Ethernet type traffic to 
drop.
destination-mac-
address mac-
address-mask
Enter a MAC address and mask in the nn:nn:nn:nn:nn format.
For the MAC address mask, specify which bits in the MAC address 
must match.
The MAC ACL supports an inverse mask; therefore, a mask of 
ff:ff:ff:ff:ff:ff allows entries that do not match and a mask of 
00:00:00:00:00:00 only allows entries that match exactly.
any Enter the keyword any to match and drop specific Ethernet traffic on 
the interface.
vlan 
vlan-id
Enter the keyword vlan and then enter the VLAN ID to filter traffic 
associated with a specific VLAN. The range is 1 to 4094 and 1 to 2094 
for ExaScale (you can use IDs 1 to 4094). To filter all VLAN traffic 
specify 
VLAN 1.
245