Overview
16-4
16.1.2 deny
MAC Extended ACL Config Commands
Use this command to specify packets to reject.
Syntax
{deny}{any|host source MAC address|source MAC/source MAC address mask} {any|host
destination MAC address|destination MAC/destination MAC address mask}[vlan vlan-
id] [dot1p dot1p-value] [type value|ip|ipv6|arp|vlan|wisp | 0-65535] [log] [rule-
precedence access-list-entry precedence]
Parameters
Usage Guidelines
The deny command disallows traffic based on layer 2 (data-link layer) information. The MAC access list denies
traffic from a particular source MAC address or any MAC address. It also has an option to disallow traffic from
a list of MAC addresses based on the source mask.
The MAC access list can be configured to disallow traffic based on VLAN information and ethernet type.
The most common ethernet type are:
•
arp
•
wisp
NOTE
Use a decimal value representation of ethertypes to implement a
permit/deny/mark
designation for a packet. The command set for Extended
MAC ACLs provides hexadecimal values for each listed ethertype. The switch
supports all ethertypes. Use the decimal equvilant of the ethertype listed or for
any other type of ethertype.
Source Mask
Bit mask specifying the bits to match. Source wildcard can be any one
of the following:
•
xx:xx:xx:xx:xx:xx/xx:xx:xx:xx:xx:xx
–Source MAC
address and mask.
•
any
– Any source host.
•
host –
Exact source MAC address to match.
Destination Mask
Bit mask specifying the bits to match. Source wildcard can be any one
of the following:
•
xx:xx:xx:xx:xx:xx/xx:xx:xx:xx:xx:xx
–Destination MAC
address and mask.
•
any
– Any destination host.
•
host –
Exact destination MAC address to match.
dot1p
<0-7>
802.1p priority value to match.
rule-precedence
<1-5000>
Access-list entry precedence.
type
(
<1-65535>
|arp|ip|ipv6|vlan|wisp)
Ethertype value represented as integer or keywords for well-known
ethertypes like IP, IPv6, ARP etc.
vlan
<1-4095>
VLAN tag ID to match.
Содержание RFS7000 Series
Страница 1: ... RFS7000 Series RF Switch CLI Reference Guide ...
Страница 10: ...x RFS7000 Series CLI Reference Guide ...
Страница 30: ...Overview 1 10 ...
Страница 150: ...Overview 3 16 RFS7000 show management Mgmt Interface vlan1 Management access permitted via any vlan interface RFS7000 ...
Страница 196: ...Overview 4 46 ...
Страница 270: ...Overview 5 74 ...
Страница 284: ...Overview 6 14 ...
Страница 294: ...Overview 7 10 ...
Страница 304: ...Overview 8 10 ...
Страница 308: ...Overview 9 4 ...
Страница 338: ...Overview 11 36 ...
Страница 366: ...Overview 12 28 ...
Страница 380: ...Overview 13 14 ...
Страница 404: ...Overview 15 2 terminal Sets terminal line parameters page 15 14 Command Description Ref ...
Страница 434: ...Overview 16 18 ...
Страница 466: ...Overview 17 32 ...
Страница 474: ...Overview 18 8 ...
Страница 504: ...Overview 19 30 ...
Страница 572: ...Overview 20 68 ...
Страница 581: ...21 9 new show alarm log count all new acknowledged severity to limit 1 65535 RFS7000 config sole ...
Страница 584: ...Overview 21 12 ...
Страница 586: ...A 2 RFS7000 Series CLI Reference Guide ...
Страница 587: ......
Страница 588: ...MOTOROLA INC 1303 E ALGONQUIN ROAD SCHAUMBURG IL 60196 http www motorola com 72E 103891 01 Revision A January 2008 ...