ECS4660-28F_Management Guide-R03

Table Of Contents
C
HAPTER
30
| Access Control Lists
MAC ACLs
– 1178
{permit | deny} tagged-802.3
{any | host source | source address-bitmask}
{any | host destination | destination address-bitmask}
[vid vid vid-bitmask] [time-range time-range-name]
no {permit | deny} tagged-802.3
{any | host source | source address-bitmask}
{any | host destination | destination address-bitmask}
[vid vid vid-bitmask]
{permit | deny} untagged-802.3
{any | host source | source address-bitmask}
{any | host destination | destination address-bitmask}
[time-range time-range-name]
no {permit | deny} untagged-802.3
{any | host
source | source address-bitmask}
{any | host destination | destination address-bitmask}
tagged-eth2 – Tagged Ethernet II packets.
untagged-eth2 – Untagged Ethernet II packets.
tagged-802.3 – Tagged Ethernet 802.3 packets.
untagged-802.3 – Untagged Ethernet 802.3 packets.
any Any MAC source or destination address.
host – A specific MAC address.
source – Source MAC address.
destination – Destination MAC address range with bitmask.
address-
bitmask
21
– Bitmask for MAC address (in hexadecimal
format).
vid – VLAN ID. (Range: 1-4094)
vid-bitmask
21
VLAN bitmask. (Range: 1-4095)
protocol – A specific Ethernet protocol number. (Range: 0-ffff hex.)
protocol-bitmask
21
– Protocol bitmask. (Range: 0-ffff hex.)
time-range-name - Name of the time range.
(Range: 1-30 characters)
DEFAULT SETTING
None
COMMAND MODE
MAC ACL
COMMAND USAGE
New rules are added to the end of the list.
The ethertype option can only be used to filter Ethernet II formatted
packets.
21. For all bitmasks, “1” means relevant and “0” means ignore.