Chapter 9
| Access Control Lists
MAC ACLs
– 334 –
Example
Console#show ipv6 access-list standard
IPv6 standard access-list david:
permit host 2009:DB9:2229::79
permit 2009:DB9:2229:5::/64
Console#
Related Commands
permit, deny (Standard IPv6 ACL) (329)
permit, deny (Extended IPv6 ACL) (330)
ipv6 access-group (332)
MAC ACLs
The commands in this section configure ACLs based on hardware addresses, packet
format, and Ethernet type. To configure MAC ACLs, first create an access list
containing the required permit or deny rules, and then bind the access list to one or
more ports.
access-list mac This command adds a MAC access list and enters MAC ACL configuration mode. Use
the no form to remove the specified ACL.
Syntax
[no] access-list mac acl-name
acl-name – Name of the ACL. (Maximum length: 16 characters, no spaces or
other special characters)
Default Setting
None
Command Mode
Global Configuration
Table 64: MAC ACL Commands
Command Function Mode
access-list mac Creates a MAC ACL and enters configuration mode GC
mac access-group Binds a MAC ACL to all ports GC
permit, deny Filters packets matching a specified source and destination
address, packet format, and Ethernet type
MAC-ACL
mac access-group Binds a MAC ACL to a port IC
show mac access-group Shows port assignments for MAC ACLs PE
show mac access-list Displays the rules for configured MAC ACLs PE