
Client Security
3-87
Web
– Specify the action (i.e., Permit or Deny). Specify the source and/or
destination addresses. Select the address type (Any, Host, or MAC). If you select
“Host,” enter a specific address (e.g., 11-22-33-44-55-66). If you select “MAC,” enter
a base address and a hexidecimal bitmask for an address range. Set any other
required criteria, such as VID, Ethernet type, or packet format. Then click Add.
Figure 3-44 Configuring MAC ACLs
CLI
– This rule permits packets from any source MAC address to the destination
address 00-e0-29-94-34-de where the Ethernet type is 0800.
Binding a Port to an Access Control List
After configuring the Access Control Lists (ACL), you can bind the ports that need to
filter traffic to the appropriate ACLs. You can assign one access list to any port – IP
ingress or MAC ingress.
Command Usage
• Each ACL can have up to 60 rules.
• This switch supports ACLs for ingress filtering only. You can only bind one IP ACL
or one MAC ACL to any port for ingress filtering.
Command Attributes
•
Port
– Fixed port or SFP module. (Range: 1-24)
•
IP
– Specifies the IP ACL to bind to a port.
Console(config-mac-acl)#permit any host 00-e0-29-94-34-de
ethertype 0800241
Console(config-mac-acl)#
Summary of Contents for ES4524M-PoE
Page 2: ......
Page 4: ...ES4524M PoE F1 0 0 5 E012008 ST R01 149100037400A...
Page 22: ...xviii Tables...
Page 26: ...xxii Figures...
Page 34: ...Introduction 1 8 1...
Page 270: ...Configuring the Switch 3 226...
Page 404: ...Command Line Interface 4 134 4...
Page 546: ...Software Specifications A 4 A...
Page 559: ......