2-234
Cisco Catalyst Blade Switch 3030 Command Reference
78-17262-01
Chapter 2 Cisco Catalyst Blade Switch 3030 Cisco IOS Commands
permit (MAC access-list configuration)
After an access control entry (ACE) is added to an access control list, an implied
deny
-
any
-
any
condition exists at the end of the list. That is, if there are no matches, the packets are denied. However,
before the first ACE is added, the list permits all packets.
For more information about MAC-named extended access lists, see the software configuration guide for
this release.
Examples
This example shows how to define the MAC-named extended access list to allow NETBIOS traffic from
any source to MAC address 00c0.00a0.03fa. Traffic matching this list is allowed.
Switch(config-ext-macl)#
permit any host 00c0.00a0.03fa netbios
This example shows how to remove the permit condition from the MAC-named extended access list:
Switch(config-ext-macl)#
no permit any 00c0.00a0.03fa 0000.0000.0000 netbios
This example permits all packets with Ethertype 0x4321:
Switch(config-ext-macl)#
permit any any 0x4321 0
You can verify your settings by entering the
show access-lists
privileged EXEC command.
Related Commands
Command
Description
deny (MAC access-list
configuration)
Denies non-IP traffic to be forwarded if conditions are matched.
mac access-list extended
Creates an access list based on MAC addresses for non-IP traffic.
show access-lists
Displays access control lists configured on a switch.