Chapter 10
| Access Control Lists
MAC ACLs
– 334 –
time-range-name
- Name of the time range. (Range: 1-32
characters)
Default Setting
None
Command Mode
MAC ACL
Command Usage
◆
New rules are added to the end of the list.
◆
The
ethertype
option can only be used to filter Ethernet II formatted
packets.
◆
A detailed listing of Ethernet protocol types can be found in RFC 1060. A
few of the more common types include the following:
■
0800 - IP
■
0806 - ARP
■
8137 - IPX
◆
If an Extended IPv4 rule and MAC rule match the same packet, and these
rules specify a “permit” entry and “deny” entry, the “deny” action takes
precedence.
Example
This rule permits packets from any source MAC address to the destination
address 00-e0-29-94-34-de where the Ethernet type is 0800.
Console(config-mac-acl)#permit any host 00-e0-29-94-34-de ethertype 0800
Console(config-mac-acl)#
Related Commands
access-list mac (331)
Time Range (145)
mac access-group
This command binds a MAC ACL to a port. Use the
no
form to remove the
port.
Syntax
mac access-group
acl-name
in
[
time-range
time-range-name
] [
counter
]
no
mac access-group
acl-name
in
acl-name
– Name of the ACL. (Maximum length: 32 characters)
in
– Indicates that this list applies to ingress packets.