Usage
Information
When you use the
log
option, the CP processor logs details about the packets that match.
Depending on how many packets match the log entry and at what rate, the CP may become
busy as it has to log these packets’ details.
NOTE: When ACL logging and byte counters are configured simultaneously, byte counters
may display an incorrect value. Configure packet counters with logging instead.
Related
Commands
deny
– configures a MAC ACL filter to drop packets.
seq
– configure a MAC ACL filter with a specified sequence number.
seq
Configure a filter with a specific sequence number.
C-Series, E-Series, S-Series, Z-Series
Syntax
seq
sequence-number
{deny | permit} {any | host
mac-address
|
mac-source-address mac-source-address-mask
} {any | host
mac-
address
|
mac-destination-address mac-destination-address-mask
}
[
ethertype operator
] [count [byte]] [log] [monitor]
To delete a filter, use the
no seq
sequence-number
command.
Parameters
sequence-
number
Enter a number as the filter sequence number. The range is zero (0) to
65535.
deny
Enter the keyword
deny
to drop any traffic matching this filter.
permit
Enter the keyword
permit
to forward any traffic matching this filter.
any
Enter the keyword
any
to filter all packets.
host
mac-
address
Enter the keyword
host
and then enter a MAC address to filter
packets with that host address.
mac-source-
address
Enter a MAC address in nn:nn:nn:nn:nn:nn format.
The MAC ACL supports an inverse mask; therefore, a mask of
ff:ff:ff:ff:ff:ff allows entries that do not match and a mask of
00:00:00:00:00:00 only allows entries that match exactly.
mac-source-
address-mask
Specify which bits in the MAC address must be matched.
mac-destination-
address
Enter the destination MAC address and mask in nn:nn:nn:nn:nn:nn
format.
mac-destination-
address-mask
Specify which bits in the MAC address must be matched.
The MAC ACL supports an inverse mask; therefore, a mask of
ff:ff:ff:ff:ff:ff allows entries that do not match and a mask of
00:00:00:00:00:00 only allows entries that match exactly.
ethertype
operator
(OPTIONAL) To filter based on protocol type, enter one of the
following Ethertypes:
•
ev2
- is the Ethernet II frame format.
297
Summary of Contents for Force10 S4810P
Page 1: ...FTOS Command Line Reference Guide for the S4810 System FTOS 9 1 0 0 ...
Page 48: ...48 ...
Page 62: ...62 ...
Page 92: ...92 ...
Page 102: ...102 ...
Page 202: ...202 ...
Page 216: ...216 ...
Page 334: ...334 ...
Page 564: ...564 ...
Page 570: ...570 ...
Page 594: ...594 ...
Page 632: ...632 ...
Page 642: ...642 ...
Page 662: ...662 ...
Page 670: ...Related Commands clear ip dhcp snooping clears the contents of the DHCP binding table 670 ...
Page 688: ...688 ...
Page 702: ...702 ...
Page 712: ...712 ...
Page 723: ...Related Commands show gvrp displays the GVRP configuration 723 ...
Page 724: ...724 ...
Page 736: ...736 ...
Page 900: ...900 ...
Page 934: ...934 ...
Page 958: ...958 ...
Page 966: ...966 ...
Page 1018: ...1018 ...
Page 1026: ...1026 ...
Page 1086: ...1086 ...
Page 1100: ...1100 ...
Page 1116: ...1116 ...
Page 1164: ...1164 ...
Page 1268: ...1268 ...
Page 1276: ...1276 ...
Page 1286: ...1286 ...
Page 1300: ...1300 ...
Page 1376: ...1376 ...
Page 1390: ...1390 ...
Page 1460: ...1460 ...
Page 1512: ...1512 ...
Page 1518: ...1518 ...
Page 1528: ...1528 ...
Page 1538: ...1538 ...
Page 1552: ...1552 ...
Page 1572: ...1572 ...
Page 1612: ...1612 ...