Table 301: Add Access Control List Rule Fields (continued)
Field
Description
Routing
IPv6 ACL rule to match on routed packets.
Match Criteria (MAC ACLs)
The fields in this section specify the criteria to use to determine whether an
Ethernet frame matches the rule. The fields described below apply to MAC
ACLs.
Every
When this option is selected, all packets will match the rule and will be either
permitted or denied. This option is exclusive to all other match criteria, so if
Every is selected, no other match criteria can be configured. To configure
specific match criteria, this option must be clear.
CoS
The 802.1p user priority value to match within the Ethernet frame.
Secondary CoS
The secondary 802.1p user priority value to match within the Ethernet frame.
Ethertype
The EtherType value to match in an Ethernet frame. Specify the number
associated with the EtherType or specify one of the following keywords:
AppleTalk, ARP, IBM SNA, IPv4, IPv6, IPX, MPLS, Unicast, NETBIOS, NOVELL,
PPPoE, or RARP.
Source MAC Address / Mask
The MAC address to match to an Ethernet frame's source port MAC address.
If desired, enter the MAC mask associated with the source MAC to match. The
MAC address mask specifies which bits in the source MAC to compare
against an Ethernet frame.
Use Fs and zeros in the MAC mask, which is in a wildcard format. An F means
that the bit is not checked, and a zero in a bit position means that the data
must equal the value given for that bit. For example, if the MAC address is
aa_bb_cc_dd_ee_ff, and the mask is 00_00_ff_ff_ff_ff, all MAC addresses
with aa_bb_xx_xx_xx_xx result in a match (where x is any hexadecimal
number).
Destination MAC Address /
Mask
The MAC address to match to an Ethernet frame's destination port MAC
address. If desired, enter the MAC Mask associated with the destination MAC
to match. The MAC address mask specifies which bits in the destination MAC
to compare against an Ethernet frame. Use F's and zeros in the MAC mask,
which is in a wildcard format. An F means that the bit is not checked, and a
zero in a bit position means that the data must equal the value given for that
bit. For example, if the MAC address is aa_bb_cc_dd_ee_ff, and the mask is
00_00_ff_ff_ff_ff, all MAC addresses with aa_bb_xx_xx_xx_xx result in a
match (where x is any hexadecimal number).
VLAN
The VLAN ID to match within the Ethernet frame.
Secondary VLAN
The secondary VLAN ID to match within the Ethernet frame.
Rule Attributes
The fields in this section provide information about the actions to take on a
frame or packet that matches the rule criteria. The attributes specify actions
other than the basic Permit or Deny actions.
Assign Queue
The number that identifies the hardware egress queue that will handle all
packets matching this rule.
Configuring Quality of Service
ExtremeSwitching 200 Series: Administration Guide
306