![Dell PowerConnect 3500 Series Cli Reference Manual Download Page 97](http://html.mh-extra.com/html/dell/powerconnect-3500-series/powerconnect-3500-series_cli-reference-manual_86069097.webp)
ACL Commands
97
Example
The following example shows how to create a MAC ACL with permit rules.
deny (MAC)
The
deny
MAC-Access List Configuration mode command denies
traffic if the conditions defined in the
deny statement match.
Syntax
•
deny [disable-port] {any|{
source source- wildcard
} {any|{
destination destination- wildcard
}} [vlan
vlan-id
] [cos
cos cos-wildcard
] [ethtype
eth-type
]
•
disable-port —
Indicates that the port is disabled if the condition is matched.
•
source
— Specifies the MAC address of the host from which the packet was sent.
•
source-wildcard
— Specifies wildcard bits to the source MAC address by placing 1s in bit positions
to be ignored.
•
any
— Specify a MAC address and mask. For example, to set 00:00:00:00:10:XX use the Mac
address 00:00:00:00:10:00 and mask 00:00:00:00:00:FF.
•
destination
— Specifies the MAC address of the host to which the packet is being sent.
•
destination-wildcard
— Specifies wildcard bits to the destination MAC address by placing 1s in bit
positions to be ignored.
•
vlan-id
— Specifies the vlan id of the packet. (Range: 1 - 4094)
•
cos
— Specifies the packets’s Class of Service (CoS). (Range: 0 - 7)
•
cos-wildcard
— Specifies wildcard bits to be applied to the CoS.
•
eth-type
— Specifies the packet’s Ethernet type in hexadecimal format. (0 - 05dd-ffff {hex})
Default Configuration
No MAC access list is defined.
Command Mode
MAC-Access List Configuration mode.
User Guidelines
•
MAC BPDU packets cannot be denied.
•
Each MAC address in the ACL is a ACE (Access Control Element) and can only be removed by deleting
the ACL using the
no ip access-list
Global Configuration mode command or the Web-based interface.
Console(config)#
mac access-list
macl-acl1
Console(config-mac-al)#
permit
06:a6 00:00:00:00:00:00 any vlan 6
book.book Page 97 Thursday, December 18, 2008 7:40 PM
Summary of Contents for PowerConnect 3500 Series
Page 62: ...62 Command Groups book book Page 62 Thursday December 18 2008 7 40 PM ...
Page 80: ...80 Command Modes book book Page 80 Thursday December 18 2008 7 40 PM ...
Page 124: ...124 Address Table Commands book book Page 124 Thursday December 18 2008 7 40 PM ...
Page 162: ...162 DHCP Snooping book book Page 162 Thursday December 18 2008 7 40 PM ...
Page 244: ...244 Line Commands book book Page 244 Thursday December 18 2008 7 40 PM ...
Page 266: ...266 LLDP Commands book book Page 266 Thursday December 18 2008 7 40 PM ...
Page 276: ...276 Login Banner book book Page 276 Thursday December 18 2008 7 40 PM ...
Page 280: ...280 PHY Diagnostics Commands book book Page 280 Thursday December 18 2008 7 40 PM ...
Page 290: ...290 Power over Ethernet Commands book book Page 290 Thursday December 18 2008 7 40 PM ...
Page 294: ...294 Port Channel Commands book book Page 294 Thursday December 18 2008 7 40 PM ...
Page 298: ...298 Port Monitor Commands book book Page 298 Thursday December 18 2008 7 40 PM ...
Page 310: ...310 QoS Commands book book Page 310 Thursday December 18 2008 7 40 PM ...
Page 318: ...318 RADIUS Commands book book Page 318 Thursday December 18 2008 7 40 PM ...
Page 414: ...414 Syslog Commands book book Page 414 Thursday December 18 2008 7 40 PM ...
Page 440: ...440 TACACS Commands book book Page 440 Thursday December 18 2008 7 40 PM ...
Page 452: ...452 TIC Commands book book Page 452 Thursday December 18 2008 7 40 PM ...
Page 460: ...460 Tunnel book book Page 460 Thursday December 18 2008 7 40 PM ...
Page 492: ...492 VLAN Commands book book Page 492 Thursday December 18 2008 7 40 PM ...
Page 500: ...500 Voice VLAN book book Page 500 Thursday December 18 2008 7 40 PM ...
Page 514: ...514 Web Server book book Page 514 Thursday December 18 2008 7 40 PM ...