Licensing Requirements for MAC ACLs
This table shows the licensing requirements for this feature.
License Requirement
Product
MAC ACLs require no license. Any feature not included in a license package is bundled with
the nx-os image and is provided at no extra charge to you. For an explanation of the Cisco
NX-OS licensing scheme, see the
Cisco NX-OS Licensing Guide
.
Cisco
NX-OS
Guidelines and Limitations for MAC ACLs
MAC ACLs have the following configuration guidelines and limitations:
• MAC ACLs apply to ingress traffic only.
• If you try to apply too many ACL entries, the configuration might be rejected.
• MAC packet classification is not supported when a MAC ACL is applied as part of a VACL.
• MAC packet classification is not supported when MAC ACLs are used as match criteria for QoS policies
on Cisco Nexus 9300 Series switch 40G uplink ports.
• When you define a MAC ACL on the non EX/FX Cisco Nexus 9000 Series switches, you must define
the ethertype for the traffic to be appropriately matched.
• Mac-packet classify knob is partially supported on the Cisco Nexus 9300-EX platform switches. In the
absence of a direct field for marking the packet as an L2 packet, the switches match all packets with
certain fields, such as src_mac, dst_mac, and vlan in the key field. However, they cannot match on the
eth_type field. Therefore, if you install two rules with identical fields, except the MAC protocol number
field, then the match conditions will remain identical in the hardware. Hence, although the first entry in
the rule sequence will hit for all the packets for all the protocol numbers, the MAC protocol number will
be a no-op when the mac-packet classify is configured.
Default Settings for MAC ACLs
This table lists the default settings for MAC ACL parameters.
Table 30: Default MAC ACLs Parameters
Default
Parameters
No MAC ACLs exist by default
MAC ACLs
Implicit rules apply to all ACLs
ACL rules
Cisco Nexus 9000 Series NX-OS Security Configuration Guide, Release 9.x
286
Configuring MAC ACLs
Licensing Requirements for MAC ACLs