ECS4660-28F_Management Guide-R03

Table Of Contents
C
HAPTER
30
| Access Control Lists
MAC ACLs
– 1179
A detailed listing of Ethernet protocol types can be found in RFC 1060.
A few of the more common types include the following:
0800 - IP
0806 - ARP
8137 - IPX
EXAMPLE
This rule permits packets from any source MAC address to the destination
address 00-e0-29-94-34-de where the Ethernet type is 0800.
Console(config-mac-acl)#permit any host 00-e0-29-94-34-de ethertype 0800
Console(config-mac-acl)#
RELATED COMMANDS
access-list mac (1176)
Time Range (957)
mac access-group This command binds a MAC ACL to a port. Use the no form to remove the
port.
SYNTAX
mac access-group acl-name {in | out}
[time-range time-range-name] [counter]
no mac access-group acl-name {in |
out}
acl-name – Name of the ACL. (Maximum length: 16 characters)
in – Indicates that this list applies to ingress packets.
out – Indicates that this list applies to egress packets.
time-range-name - Name of the time range. (Range: 1-30
characters)
counter Enables counter for ACL statistics.
DEFAULT SETTING
None
COMMAND MODE
Interface Configuration (Ethernet)
COMMAND USAGE
If an ACL is already bound to a port and you bind a different ACL to it, the
switch will replace the old binding with the new one.
EXAMPLE
Console(config)#interface ethernet 1/2
Console(config-if)#mac access-group jerry in
Console(config-if)#