Users Guide
• Use the no permit {any | host mac-address | mac-source-address mac-source-
address-mask} {any | mac-destination-address mac-destination-address-mask}
command.
Parameters
any Enter the keyword any to forward all packets.
host Enter the keyword host then a MAC address to forward packets with that host address.
mac-source-
address
Enter a MAC address in nn:nn:nn:nn:nn:nn format.
mac-source-
address-mask
(OPTIONAL) Specify which bits in the MAC address must match.
The MAC ACL supports an inverse mask; therefore, a mask of ::::: allows entries
that do not match and a mask of 00:00:00:00:00:00 only allows entries that match
exactly.
mac-destination-
address
Enter the destination MAC address and mask in nn:nn:nn:nn:nn:nn format.
mac-destination-
address-mask
Specify which bits in the MAC address must be matched.
The MAC ACL supports an inverse mask; therefore, a mask of ::::: allows entries
that do not match and a mask of 00:00:00:00:00:00 only allows entries that match
exactly.
ethertype operator (OPTIONAL) To lter based on protocol type, enter one of the following Ethertypes:
• ev2 - is the Ethernet II frame format
• llc - is the IEEE 802.3 frame format
• snap - is the IEEE 802.3 SNAP frame format
count (OPTIONAL) Enter the keyword count to count packets the lter processes.
byte (OPTIONAL) Enter the keyword byte to count bytes the lter processes.
Defaults Not congured.
Command Modes CONFIGURATION-MAC ACCESS LIST-EXTENDED
Supported Modes Full–Switch
Command History
Version Description
9.9(0.0) Introduced on the FN IOM.
8.3.16.1 Introduced on the MXL 10/40GbE Switch IO Module.
Related Commands
deny — congures a MAC ACL lter to drop packets.
seq — congure a MAC ACL lter with a specied sequence number.
Access Control Lists (ACL) 193