4 Command Line Interface

Command Mode

Interface Configuration (Ethernet)

Command Usage

A port can only be bound to one ACL.

If a port is already bound to an ACL and you bind it to a different ACL, the switch will replace the old binding with the new one.

You must configure a mask for an ACL rule before you can bind it to a port.

Example

Console(config)#int eth 1/25

Console(config-if)#ip access-group david in

Console(config-if)#

Related Commands

show ip access-list(4-143)

show ip access-group

This command shows the ports assigned to IP ACLs.

Command Mode

Privileged Exec

Example

Console#show ip access-group

Interface ethernet 1/25

IP access-list david in

Console#

Related Commands

ip access-group(4-143)

MAC ACLs

The commands in this section configure ACLs based on hardware addresses, packet format, and Ethernet type. To configure MAC ACLs, first create an access list containing the required permit or deny rules, and then bind the access list to one or more ports

Table 4-40 MAC ACL Commands

Command

Function

Mode

Page

 

 

 

 

access-list mac

Creates a MAC ACL and enters configuration mode

GC

4-145

 

 

 

 

permit, deny

Filters packets matching a specified source and

MAC-ACL

4-146

 

destination address, packet format, and Ethernet type

 

 

show mac access-list

Displays the rules for configured MAC ACLs

PE

4-147

 

 

 

 

4-144

Page 440
Image 440
Accton Technology ES3528M-SFP MAC ACLs, Show ip access-group, Show ip access-list4-143, MAC ACL Commands Function Mode