Access Control Lists (ACL) |
125
Example
Figure 6-8.
mac access-list extended Command Example
Related
Commands
permit
Configure a filter to pass packets matching the criteria specified.
Syntax
permit
{
any
|
host
mac-address
|
mac-source-address
mac-source-address-mask
} {
any
|
host
mac-address
|
mac-destination-address
mac-destination-address-mask
} [
ethertype operator
]
[
count
[
byte
]]
To remove this filter, you have two choices:
•
Use the
no
seq
sequence-number
command if you know the filter’s sequence number.
•
Use the
no
permit
{
any
|
host
mac-address
|
mac-source-address mac-source-address-mask
}
{
any
|
mac-destination-address mac-destination-address-mask
} command.
Parameters
FTOS(conf)#mac access-list extended TestMATExt
FTOS(conf-ext-macl)#remark 5 IPv4
FTOS(conf-ext-macl)#seq 10 permit any any ev2 eq 800 count bytes
FTOS(conf-ext-macl)#remark 15 ARP
FTOS(conf-ext-macl)#seq 20 permit any any ev2 eq 806 count bytes
FTOS(conf-ext-macl)#remark 25 IPv4
FTOS(conf-ext-macl)#seq 30 permit any any ev2 eq 86dd count bytes
FTOS(conf-ext-macl)#seq 40 permit any any count bytes
FTOS(conf-ext-macl)#exit
FTOS(conf)#do show mac accounting access-list snickers interface tengig0/47 in
Extended mac access-list snickers on TenGigabitEthernet 0/47
seq 10 permit any any ev2 eq 800 count bytes (559851886 packets 191402152148
bytes)
seq 20 permit any any ev2 eq 806 count bytes (74481486 packets 5031686754
bytes)
seq 30 permit any any ev2 eq 86dd count bytes (7751519 packets 797843521 bytes)
mac access-list standard
Configures a standard MAC access list.
show mac accounting access-list
Displays
MAC access list configurations and counters (if
configured).
any
Enter the keyword
any
to forward all packets.
host
Enter the keyword
host
followed by a MAC address to
forward packets with that host address.
mac-source-address
Enter the source MAC address in nn:nn:nn:nn:nn:nn format.
mac-source-address-mask
Specify which bits in the MAC address must be matched.
The MAC ACL supports an inverse mask, therefore, a mask of
ff:ff:ff:ff:ff:ff allows entries that do not match and a mask of
00:00:00:00:00:00 only allows entries that match exactly.
mac-destination-address
Enter the destination MAC address and mask in
nn:nn:nn:nn:nn:nn format.
mac-destination-address-mask
Specify which bits in the MAC address must be matched.
The MAC ACL supports an inverse mask, therefore, a mask of
ff:ff:ff:ff:ff:ff allows entries that do not match and a mask of
00:00:00:00:00:00 only allows entries that match exactly.
Содержание Force10 MXL Blade
Страница 80: ...80 Control and Monitoring w w w d e l l c o m s u p p o r t d e l l c o m ...
Страница 142: ...142 Access Control Lists ACL w w w d e l l c o m s u p p o r t d e l l c o m ...
Страница 146: ...146 Bare Metal Provisioning w w w d e l l c o m s u p p o r t d e l l c o m ...
Страница 152: ...152 Content Addressable Memory CAM w w w d e l l c o m s u p p o r t d e l l c o m ...
Страница 186: ...186 Data Center Bridging w w w d e l l c o m s u p p o r t d e l l c o m ...
Страница 204: ...204 Dynamic Host Configuration Protocol DHCP w w w d e l l c o m s u p p o r t d e l l c o m ...
Страница 216: ...216 FIP Snooping w w w d e l l c o m s u p p o r t d e l l c o m ...
Страница 226: ...226 GARP VLAN Registration GVRP w w w d e l l c o m s u p p o r t d e l l c o m ...
Страница 234: ...234 Internet Group Management Protocol IGMP w w w d e l l c o m s u p p o r t d e l l c o m ...
Страница 330: ...330 iSCSI Optimization w w w d e l l c o m s u p p o r t d e l l c o m ...
Страница 354: ...354 Layer 2 w w w d e l l c o m s u p p o r t d e l l c o m ...
Страница 370: ...370 Link Layer Discovery Protocol LLDP w w w d e l l c o m s u p p o r t d e l l c o m ...
Страница 384: ...384 Multiple Spanning Tree Protocol MSTP w w w d e l l c o m s u p p o r t d e l l c o m ...
Страница 438: ...438 Port Monitoring w w w d e l l c o m s u p p o r t d e l l c o m ...
Страница 448: ...448 Private VLAN PVLAN w w w d e l l c o m s u p p o r t d e l l c o m ...
Страница 490: ...490 Quality of Service QoS w w w d e l l c o m s u p p o r t d e l l c o m ...
Страница 518: ...518 Remote Monitoring RMON w w w d e l l c o m s u p p o r t d e l l c o m ...
Страница 530: ...530 Rapid Spanning Tree Protocol RSTP w w w d e l l c o m s u p p o r t d e l l c o m ...
Страница 570: ...570 Security w w w d e l l c o m s u p p o r t d e l l c o m ...
Страница 578: ...578 sFlow w w w d e l l c o m s u p p o r t d e l l c o m ...
Страница 620: ...620 Stacking Commands w w w d e l l c o m s u p p o r t d e l l c o m ...
Страница 654: ...654 Uplink Failure Detection UFD w w w d e l l c o m s u p p o r t d e l l c o m ...
Страница 693: ...Debugging and Diagnostics 693 ...
Страница 694: ...694 Debugging and Diagnostics w w w d e l l c o m s u p p o r t d e l l c o m ...
Страница 712: ...712 Index w w w d e l l c o m s u p p o r t d e l l c o m ...
Страница 713: ...Index 713 ...
Страница 714: ...714 Index w w w d e l l c o m s u p p o r t d e l l c o m ...
Страница 715: ...Index 715 ...
Страница 716: ...716 Index w w w d e l l c o m s u p p o r t d e l l c o m ...
Страница 717: ...Index 717 ...
Страница 718: ...718 Index w w w d e l l c o m s u p p o r t d e l l c o m ...
Страница 728: ...728 Command Index w w w d e l l c o m s u p p o r t d e l l c o m write 78 write memory 25 ...
Страница 729: ...Command Index 729 ...
Страница 730: ...730 Command Index w w w d e l l c o m s u p p o r t d e l l c o m ...
Страница 731: ...Command Index 731 ...
Страница 732: ...732 Command Index w w w d e l l c o m s u p p o r t d e l l c o m ...