Parameters
sequence-
number
Enter a number from 0 to 4294967290.
deny Enter the keyword deny to drop all traffic meeting the filter criteria..
permit Enter the keyword permit to forward all traffic meeting the filter
criteria.
destination-mac-
address mac-
address-mask
Enter a MAC address and mask in the nn:nn:nn:nn:nn format.
For the MAC address mask, specify which bits in the MAC address
must match.
The MAC ACL supports an inverse mask; therefore, a mask of
ff:ff:ff:ff:ff:ff allows entries that do not match and a mask of
00:00:00:00:00:00 only allows entries that match exactly.
any Enter the keyword any to match and drop any ARP traffic on the
interface.
vlan
vlan-id
Enter the keyword vlan followed by the VLAN ID to filter traffic
associated with a specific VLAN. The range is 1 to 4094 and 1 to 2094
for ExaScale (you can use IDs 1 to 4094). To filter all VLAN traffic
specify
VLAN 1.
ip-address
Enter an IP address in dotted decimal format (A.B.C.D) as the target
IP address of the ARP.
opcode
code-
number
Enter the keyword opcode and then enter the number of the ARP
opcode. The range is 1 to 16.
count (OPTIONAL) Enter the keyword count to count packets the filter
processes.
byte (OPTIONAL) Enter the keyword byte to count bytes the filter
processes.
log (OPTIONAL, E-Series only) Enter the keyword log to have the
information kept in an ACL log file.
order (OPTIONAL) Enter the keyword order to specify the QoS priority for
the ACL entry. The range is 0 to 254 (where 0 is the highest priority
and 254 is the lowest; lower-order numbers have a higher priority). If
you do not use the keyword order, the ACLs have the lowest order
by default (255).
monitor (OPTIONAL) Enter the keyword monitor when the rule is describing
the traffic that you want to monitor and the ACL in which you are
creating the rule is applied to the monitored interface.
NOTE: For more information, refer to the Flow-based Monitoring
section in the Port Monitoring chapter of the
FTOS Configuration
Guide
.
Defaults Not configured
Command Modes CONFIGURATION-EXTENDED-ACCESS-LIST
256