Users Guide
mac access-group
Apply a MAC ACL to trac entering or exiting an interface. You can apply a MAC ACL on a physical, port-channel, or VLAN interface.
Syntax
mac access-group access-list-name {in [vlan vlan-range] | out}
To delete a MAC access-group, use the no mac access-group mac-list-name command.
Parameters
access-list-name Enter the name of a congured MAC access list, up to 140 characters.
NOTE: This option is available only with the keyword in option.
vlan vlan-range (OPTIONAL) Enter the keyword vlan and then enter a range of VLANs. The range is
from 1 to 4094 (you can use IDs 1 to 4094).
NOTE: This option is available only with the keyword in option.
optimized Enter the keyword optimized to enable ACL optimization.
in Enter the keyword in to congure the ACL to lter incoming trac.
out Enter the keyword out to congure the ACL to lter outgoing trac.
NOTE:
1. If the MAC ACL is applied on VLAN, none of the VLAN members should have an access list applied for that
VLAN.
2. If the MAC ACL is applied on a Physical or Port Channel interface, the VLAN in which this port is
associated should not have an access list applied.
3. If the MAC ACL is applied on a VLAN, then that VLAN should not belong to VLAN ACL group.
4. If the MAC ACL is applied on a VLAN ACL group, then none of the VLANs in that group should have an
access list applied on it.
Defaults none
Command Modes INTERFACE
Command History
This guide is platform-specic. For command information about other platforms, see the relevant Dell EMC
Networking OS Command Line Reference Guide.
Version Description
9.10(0.1) Introduced on the S6010-ON and S4048T-ON.
9.10(0.0) Introduced on the S3148.
9.10(0.0) Introduced on the S6100-ON.
9.8(2.0) Introduced on the S3100 series.
9.8(1.0) Introduced on the Z9100–ON.
9.8(0.0P5) Introduced on the S4048-ON.
9.8(0.0P2) Introduced on the S3048-ON.
250 Access Control Lists (ACL)