CLI Reference Guide-R02

Table Of Contents
Chapter 10
| Access Control Lists
MAC ACLs
– 383 –
no {permit | deny} untagged-eth2
{any | host source | source address}
{any | host destination | destination address}
[ip {any | host source-ip | source-ip network-mask}
{any | host destination-ip | destination-ip network-mask}]
[ipv6 {any | host source-ipv6 | source-ipv6/prefix-length}
{any | host destination-ipv6 | destination-ipv6/prefix-length}]
[ethertype ethertype [ethertype-bitmask]]
[protocol protocol]
[l4-source-port sport [port-bitmask]]
[l4-destination-port dport [port-bitmask]]
{permit | deny} tagged-802.3
{any | host source | source address
}
{any | host destination | destination address}
[cos cos cos-bitmask] [vid vid vid-bitmask]
[time-range time-range-name]
no {permit | deny} tagged-802.3
{any | host source | source address}
{any | host destination | destination address}
[cos cos cos-bitmask] [vid vid vid-bitmask]
{permit | deny} untagged-802.3
{any | host source | source address}
{any | host destination | destination address}
[time-range time-range-name]
no {permit | deny} untagged-802.3
{any | host source | source address}
{
any | host destination | destination address}
tagged-eth2 – Tagged Ethernet II packets.
untagged-eth2 – Untagged Ethernet II packets.
tagged-802.3 – Tagged Ethernet 802.3 packets.
untagged-802.3 – Untagged Ethernet 802.3 packets.
any – Any MAC, IPv4 or IPv6 source or destination address.
host – A specific MAC, IPv4 or IPv6 address.
source – Source MAC, IPv4 or IPv6 address.
destination – Destination MAC, IPv4 or IPv6 address.
network-
mask
– Network mask for IP subnet. This mask identifies the host
address bits used for routing to specific subnets.
prefix-length - Length of IPv6 prefix. A decimal value indicating how many
contiguous bits (from the left) of the address comprise the prefix; i.e., the
network portion of the address. (Range: 0-128)
cos – Class-of-Service value (Range: 0-7)
cos-bitmask
6
– Class-of-Service bitmask. (Range: 0-7)