User`s manual
User’s Manual 163
permit, deny Filters packets meeting the specified criteria, including source and
destination IP address, TCP/UDP port number, protocol type, and
TCP control code
EXT-
ACL
show ip access-list Displays the rules for configured IP ACLs PE
access-list ip mask-
precedence
Changes to the mode for configuring access control masks GC
Mask Sets a precedence mask for the ACL rules IP-Mask
show access-list ip mask-
precedence
Shows the ingress or egress rule masks for IP ACLs PE
ip access-group Adds a port to an IP ACL IC
show ip access-group Shows port assignments for IP ACLs PE
map access-list ip Sets the CoS value and corresponding output queue for packets
matching an ACL rule
IC
show map access-list ip Shows CoS value mapped to an access list for an interface PE
match access-list ip Changes the 802.1p priority, IP Precedence, or DSCP Priority of a
frame matching the defined rule (For example, also called packet
marking)
IC
show marking Displays the current configuration for packet marking PE
15.5.2 MAC ACLs
The following table lists the MAC access control list commands.
Command Function Mode
access-list mac Creates a MAC ACL and enters configuration mode GC
permit, deny Filters packets matching a specified source and destination
address, packet format, and Ethernet type
MAC-ACL
show mac access-list Displays the rules for configured MAC ACLs PE
access-list mac mask-
precedence
Changes to the mode for configuring access control masks GC
Mask Sets a precedence mask for the ACL rules MAC-
Mask
show access-list mac
mask-precedence
Shows the ingress or egress rule masks for MAC ACLs PE
mac access-group Adds a port to a MAC ACL IC
show mac access-group Shows port assignments for MAC ACLs PE