EasyManua.ls Logo

Edge-Core ES3528MV2 - Page 965

Edge-Core ES3528MV2
1480 pages
Print Icon
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Loading...
C
HAPTER
26
| Access Control Lists
MAC ACLs
– 965 –
EXAMPLE
Console(config)#access-list mac jerry
Console(config-mac-acl)#
RELATED COMMANDS
permit, deny (965)
mac access-group (968)
show mac access-list (969)
permit, deny
(MAC ACL)
This command adds a rule to a MAC ACL. The rule filters packets matching
a specified MAC source or destination address (i.e., physical layer address),
or Ethernet protocol type. Rules can also filter packets based on IPv4/v6
addresses, including Layer 4 ports and protocol types. Use the no form to
remove a rule.
SYNTAX
{permit | deny}
{any | host source | source address-bitmask}
{any | host destination | destination address-bitmask}
[vid vid vid-bitmask] [ethertype ethertype [ethertype-bitmask]]
{{ip {any | host source-ip | source-ip network-mask}
{any | host destination-ip | destination-ip network-mask}
{ipv6 {any | host source-ipv6 | source-ipv6/prefix-length}
{any | host destination-ipv6 | destination-ipv6/prefix-length}}
[protocol protocol]
[l4-source-port sport [port-bitmask]]
[l4-destination-port dport [port-bitmask]}]
[time-range time-range-name]
no {permit | deny}
{any
| host source | source address-bitmask}
{any | host destination | destination address-bitmask}
[vid vid vid-bitmask] [ethertype ethertype [ethertype-bitmask]]
{{ip {any | host source-ip | source-ip network-mask}
{any | host destination-ip | destination-ip network-mask}
{ipv6 {any | host source-ipv6 | source-ipv6/prefix-length}
{any | host destination-ipv6 | destination-ipv6/prefix-length}}
[protocol protocol]
[l4-source-port sport [port-bitmask]]
[l4-destination-port dport [port-bitmask]}]
Note:
The default is for Ethernet II packets.

Table of Contents

Related product manuals