• For a 10-Gigabit Ethernet interface, enter the keyword
TenGigabitEthernet
and then enter the slot/port
information.
• For a 40-Gigabit Ethernet interface, enter the keyword
fortyGigE
and then enter the slot/port information.
• For a VLAN interface enter the keyword VLAN and then
the
vlan id
in | out
Identify whether ACL is applied on ingress or egress side.
Command
Modes
• EXEC
• EXEC Privilege
Command
History
Version 8.3.16.1
Introduced on the MXL 10/40GbE Switch IO Module.
Usage
Information
The ACL hit counters in this command increment the counters for each matching
rule, not just the first matching rule.
Example
Dell#show mac accounting access-list TestMac interface
tengigabitethernet 0/89 in
Ingress Standard mac access-list TestMac on TenGigabitEthernet
0/89
Total cam count 2
seq 5 permit aa:aa:aa:aa:00:00 00:00:00:00:ff:ff count (0
packets)
seq 10 deny any count (20072594 packets)
Dell#
Standard MAC ACL Commands
When you create an access control list without any rule and then apply it to an interface, the ACL
behavior reflects implicit permit. These commands configure standard MAC ACLs.
The MXL 10/40GbE Switch IO Module platform supports both Ingress and Egress MAC ACLs.
NOTE: For more information, also refer to the
Commands Common to all ACL Types
and
Common
MAC Access List Commands
sections.
deny
To drop packets with a the MAC address specified, configure a filter.
Syntax
deny {any |
mac-source-address
[
mac-source-address-mask
]}
[count [byte]] [log [interval
minutes
] [threshold—in-msgs
[count]] [monitor]
Access Control Lists (ACL)
183