Specifications
13-12
Cisco Security Appliance Command Line Configuration Guide
OL-6721-01
Chapter 13 Identifying Traffic with Access Lists
 Adding an EtherType Access List
On Cisco IOS routers, enter the appropriate command for your protocol, LDP or TDP. The interface is 
the interface connected to the security appliance.
hostname(config)# mpls ldp router-id 
interface 
force
Or
hostname(config)# tag-switching tdp router-id 
interface
 force
You can apply only one access list of each type (extended and EtherType) to each direction of an 
interface. You can also apply the same access lists on multiple interfaces.
To add an EtherType ACE, enter the following command:
hostname(config)# access-list 
access_list_name
 ethertype {permit | deny} {ipx | bpdu | 
mpls-unicast | mpls-multicast | any | 
hex_number
}
The hex_number is any EtherType that can be identified by a 16-bit hexadecimal number greater than or 
equal to 0x600. See RFC 1700, “Assigned Numbers,” at http://www.ietf.org/rfc/rfc1700.txt for a list of 
EtherTypes.
Note If an EtherType access list is configured to deny all, all ethernet frames are discarded. Only physical 
protocol traffic, such as auto-negotiation, is still allowed.
When you enter the access-list command for a given access list name, the ACE is added to the end of 
the access list.
Tip Enter the access_list_name in upper case letters so the name is easy to see in the configuration. You 
might want to name the access list for the interface (for example, INSIDE), or for the purpose (for 
example, MPLS or IPX).
For example, the following sample access list allows common EtherTypes originating on the inside 
interface:
hostname(config)# access-list ETHER ethertype permit ipx
hostname(config)# access-list ETHER ethertype permit bpdu
hostname(config)# access-list ETHER ethertype permit mpls-unicast
hostname(config)# access-group ETHER in interface inside
The following access list allows some EtherTypes through the security appliance, but denies IPX:
hostname(config)# access-list ETHER ethertype deny ipx
hostname(config)# access-list ETHER ethertype permit 0x1234
hostname(config)# access-list ETHER ethertype permit bpdu
hostname(config)# access-list ETHER ethertype permit mpls-unicast
hostname(config)# access-group ETHER in interface inside
hostname(config)# access-group ETHER in interface outside
The following access list denies traffic with EtherType 0x1256, but allows all others on both interfaces:
hostname(config)# access-list nonIP ethertype deny 1256
hostname(config)# access-list nonIP ethertype permit any
hostname(config)# access-group ETHER in interface inside
hostname(config)# access-group ETHER in interface outside










