Chapter 25: Access Control Lists
MAC ACLs
– 914 –
vid
– VLAN ID. (Range: 1-4094)
vid-bitmask
–
VLAN bitmask. (Range: 1-4095)
ethertype
– A specific Ethernet protocol number. (Range: 0-ffff hex)
ethertype
-
bitmask
– Protocol bitmask. (Range: 0-ffff hex)
protocol
- IP protocol or IPv6 next header. (Range: 0-255)
For information on next headers, see
sport
3
– Protocol source port number. (Range: 0-65535)
dport
– Protocol destination port number. (Range: 0-65535)
port-bitmask
– Decimal number representing the port bits to match.
(Range: 0-65535)
time-range-name
- Name of the time range.
(Range: 1-16 characters)
D
EFAULT
S
ETTING
None
C
OMMAND
M
ODE
MAC ACL
C
OMMAND
U
SAGE
•
New rules are added to the end of the list.
•
The
ethertype
option can only be used to filter Ethernet II formatted
packets.
•
A detailed listing of Ethernet protocol types can be found in RFC 1060.
A few of the more common types include the following:
•
0800 - IP
•
0806 - ARP
•
8137 - IPX
E
XAMPLE
This rule permits packets from any source MAC address to the destination
address 00-e0-29-94-34-de where the Ethernet type is 0800.
Console(config-mac-acl)#permit any host 00-e0-29-94-34-de ethertype 0800
Console(config-mac-acl)#
R
ELATED
C
OMMANDS
3. Includes TCP, UDP or other protocol types.
Summary of Contents for SSE-G2252
Page 42: ...44 General IP Routing on page 627...
Page 603: ...Chapter 16 IP Configuration Setting the Switch s IP Address IP Version 6 609...
Page 883: ...Chapter 24 General Security Measures Port based Traffic Segmentation 894...
Page 989: ...Chapter 30 Congestion Control Commands Automatic Traffic Control Commands 1000 Console...
Page 1007: ...Chapter 33 Address Table Commands 1019...
Page 1137: ...Chapter 38 Quality of Service Commands 1150...