Specifications
5-4 VLAN Commands
clear security l2-restrict
RemovesoneormoreMACaddressesfromthelistofdestinationMACaddressestowhichclients
inaVLANareallowedtosendtrafficatLayer2.
Syntax
clear security l2-restrict vlan vlan‐id [permit-mac mac‐addr [mac‐addr] | all]
Parameters
IfyoudonotspecifyalistofMACaddressesorall,alladdressesareremoved.
Mode
Enabled.
Usage
IfyouclearallMACaddresses,Layer2forwardingisnolongerrestrictedintheVLAN.Clients
withintheVLANwillbeabletocommunicatedirectly.
Therecanbeaslightdelaybeforefunctionssuchaspingingbetweenclientsbecomeavailable
againafterLayer2restrictionsarelifted.Eventhoughpackets
arepassedimmediatelyonceLayer
2restrictionsaregone,itcantake10secondsormoreforupper‐layerprotocolstoupdatetheir
ARPcachesandregaintheirfunctionality.
ToclearthestatisticscounterswithoutremovinganyMACaddresses,usetheclearsecurityl2‐
restrictcounterscommandinstead.
Example
ThefollowingcommandremovesMACaddressaa:bb:cc:dd:ee:fffromthelistofaddressesto
whichclientsinVLANabc_airareallowedtosendtrafficatLayer 2:
RBT-8100# clear security l2-restrict vlan abc_air permit-mac
aa:bb:cc:dd:ee:ff
success: change accepted.
vlan‐id VLANnameornumber.
permit‐macmac‐
addr[mac‐addr]
ListofMACaddresses.MSSnolongerallowsclientsintheVLANtosend
traffictotheMACaddressesatLayer2.
all RemovesallMACaddressesfromthelist.