Usage
Information
The ACL hit counters in this command increment the counters for each matching rule, not just
the first matching rule.
Example
FTOS#show mac accounting access-list mac-ext interface po 1
Extended mac access-list mac-ext on GigabitEthernet 0/11
seq 5 permit host 00:00:00:00:00:11 host 00:00:00:00:00:19
count (393794576 packets)
seq 10 deny host 00:00:00:00:00:21 host 00:00:00:00:00:29
count (89076777 packets)
seq 15 deny host 00:00:00:00:00:31 host 00:00:00:00:00:39
count (0 packets)
seq 20 deny host 00:00:00:00:00:41 host 00:00:00:00:00:49
count (0 packets)
seq 25 permit any any count (0 packets)
Extended mac access-list mac-ext on GigabitEthernet 0/12
seq 5 permit host 00:00:00:00:00:11 host 00:00:00:00:00:19
count (57589834 packets)
seq 10 deny host 00:00:00:00:00:21 host 00:00:00:00:00:29
count (393143077 packets)
seq 15 deny host 00:00:00:00:00:31 host 00:00:00:00:00:39
count (0 packets)
seq 20 deny host 00:00:00:00:00:41 host 00:00:00:00:00:49
count (0 packets)
seq 25 permit any any count (0 packets)
FTOS#
Standard MAC ACL Commands
When you create an access control list without any rule and then apply it to an interface, the ACL behavior reflects
implicit permit. These commands configure standard MAC ACLs.
The C-Series and S-Series platforms (except the S4810 system) support Ingress MAC ACLs only.
The S4810 and Z9000 support both Ingress and Egress MAC ACLs.
NOTE: For more information, also refer to the
Commands Common to all ACL Types
and
Common MAC Access List
Commands
sections.
deny
Configure a filter to drop packets with a the MAC address specified.
C-Series, E-Series, S-Series, Z-Series
Syntax
deny {any |
mac-source-address
[
mac-source-address-mask
]}
[count [byte]] [log] [monitor]
To remove this filter, you have two choices:
•
Use the
no seq
sequence-number
command if you know the filter’s sequence
number.
•
Use the
no deny {any |
mac-source-address mac-source-
address-mask
}
command.
287
Содержание Force10 S4810P
Страница 1: ...FTOS Command Line Reference Guide for the S4810 System FTOS 9 1 0 0 ...
Страница 48: ...48 ...
Страница 62: ...62 ...
Страница 92: ...92 ...
Страница 102: ...102 ...
Страница 202: ...202 ...
Страница 216: ...216 ...
Страница 334: ...334 ...
Страница 564: ...564 ...
Страница 570: ...570 ...
Страница 594: ...594 ...
Страница 632: ...632 ...
Страница 642: ...642 ...
Страница 662: ...662 ...
Страница 670: ...Related Commands clear ip dhcp snooping clears the contents of the DHCP binding table 670 ...
Страница 688: ...688 ...
Страница 702: ...702 ...
Страница 712: ...712 ...
Страница 723: ...Related Commands show gvrp displays the GVRP configuration 723 ...
Страница 724: ...724 ...
Страница 736: ...736 ...
Страница 900: ...900 ...
Страница 934: ...934 ...
Страница 958: ...958 ...
Страница 966: ...966 ...
Страница 1018: ...1018 ...
Страница 1026: ...1026 ...
Страница 1086: ...1086 ...
Страница 1100: ...1100 ...
Страница 1116: ...1116 ...
Страница 1164: ...1164 ...
Страница 1268: ...1268 ...
Страница 1276: ...1276 ...
Страница 1286: ...1286 ...
Страница 1300: ...1300 ...
Страница 1376: ...1376 ...
Страница 1390: ...1390 ...
Страница 1460: ...1460 ...
Страница 1512: ...1512 ...
Страница 1518: ...1518 ...
Страница 1528: ...1528 ...
Страница 1538: ...1538 ...
Страница 1551: ...To display the type of STP guard Portfast BPDU root or loop guard enabled on a port enter the show spanning tree 0 command 1551 ...
Страница 1552: ...1552 ...
Страница 1572: ...1572 ...
Страница 1586: ... uplink state group creates an uplink state group and enables the tracking of upstream links 1586 ...
Страница 1598: ...FTOS config interface vlan 40 FTOS conf if vlan tagged TenGi 8 0 FTOS conf if vlan exit FTOS config 1598 ...
Страница 1612: ...1612 ...