15-61
Catalyst 6500 Series Switch Software Configuration Guide—Release 8.7
OL-8978-04
Chapter 15 Configuring Access Control
Configuring MAC-Based ACL Lookups for All Packet Types
This example shows how to display the flow information in the log table:
Console> (enable)
show security acl log flow ip any any
Total matched entry number = 1
Entry No. #1, IP Packet
----------------------------------------
Vlan Number : 1
Mod/Port Number : 2/1
Source IP address : 21.0.0.1
Destination IP address : 255.255.255.255
TCP Source port : 2000
TCP Destination port : 3000
Received Packet Number : 10
This example shows how to clear the log table:
Console> (enable)
clear security acl log flow
Log table is cleared.
Console> (enable)
Configuring MAC-Based ACL Lookups for All Packet Types
Note
This feature is only available with PFC3B and PFC3BXL.
These sections describe how to configure the MAC-based ACL lookups for all packet types:
•
Overview of MAC-Based ACLs, page 15-61
•
Using MAC-Based ACL Lookups for All Packet Types, page 15-62
•
Including the VLAN and CoS in MAC-Based ACLs, page 15-62
•
Configuration Guidelines, page 15-63
•
Configuring MAC-Based ACL Lookups for All Packet Types, page 15-63
Overview of MAC-Based ACLs
PFC3A supports two ACL protocol types, IP and MAC. The IP ACL matches only the IP version 4
packets and the MAC ACL matches all packet types
unsupported
by PFC3A (for more information, see
the
“Creating a Non-IP Version 4/Non-IPX VACL (MAC VACL) and Adding ACEs” section on
page 15-52
). The packet types that are supported by PFC3A are as follows: IP version 4, MPLS,
ARP/RARP, and IP version 6. However, only IP version 4 ACLs can be created in software release 8.4(1)
and earlier releases. The unsupported packet types, such as the IPX packet types, are matched using the
MAC ACL.
Note
The IPX packet types are supported with the PFC and PFC2.