Managing Device Security 
276
S3300 Smart Managed Pro Switch 
• EtherType User Value. This field is configurable if you select User Value from the 
EtherType drop-down menu. The value you enter specifies a customized EtherType 
to compare against an Ethernet frame. The valid range of values is 0x0600–0xFFFF.
• Source MAC. Requires a packet’s source port MAC address to match the address 
listed here. Enter a MAC address in the this field. The valid format is xx:xx:xx:xx:xx:xx.
• Source MAC Mask. If desired, enter the MAC mask for the source MAC address to 
match. Use Fs and zeros in the MAC mask, which is in a wildcard format. An F means 
that the bit is not checked, and a zero in a bit position means that the data must equal 
the value given for that bit. The valid format is xx:xx:xx:xx:xx:xx. A MAC mask of 
00:00:00:00:00:00 matches a single MAC address.
• VLAN. Requires a packet’s VLAN ID to match the ID listed here. Enter the VLAN ID to 
apply this criteria. The valid range is 1–4093.
• Logging. When set to Enable, logging is enabled for this ACL rule (subject to 
resource availability in the device). If the Access List Trap Flag is also enabled, this 
will cause periodic traps to be generated indicating the number of times this rule was 
hit during the current report interval. A fixed 5 minute report interval is used for the 
entire system. A trap is not issued if the ACL rule hit count is zero for the current 
interval. This field is only supported for a Deny action. 
5.  Click the Add button.
 To change the match criteria for a rule:
1.  Select the check box associated with the rule.
2.  Modify the fields as desired.
3.  Click the Apply button. 
 To delete a rule:
1.  Select the check box associated with the rule to remove.
2.  Click the Delete button.