44 Access Control List Commands

Example

Console#show ip access-group

Interface ethernet 1/2

IPv6 standard access-list david in

Console#

Related Commands

ipv6 access-group(44-11)

MAC ACLs

The commands in this section configure ACLs based on hardware addresses, packet format, and Ethernet type. To configure MAC ACLs, first create an access list containing the required permit or deny rules, and then bind the access list to one or more ports

Table 44-4 MAC ACL Commands

Command

Function

Mode

Page

 

 

 

 

access-list mac

Creates a MAC ACL and enters configuration mode

GC

44-12

 

 

 

 

permit, deny

Filters packets matching a specified source and

MAC-ACL

44-13

 

destination address, packet format, and Ethernet type

 

 

show mac access-list

Displays the rules for configured MAC ACLs

PE

44-14

 

 

 

 

mac access-group

Adds a port to a MAC ACL

IC

44-15

 

 

 

 

show mac access-group

Shows port assignments for MAC ACLs

PE

44-15

 

 

 

 

access-list mac

This command adds a MAC access list and enters MAC ACL configuration mode. Use the no form to remove the specified ACL.

Syntax

[no] access-list mac acl_name

acl_name – Name of the ACL. (Maximum length: 16 characters)

Default Setting

None

Command Mode

Global Configuration

Command Usage

When you create a new ACL or enter configuration mode for an existing ACL, use the permit or deny command to add new rules to the bottom of the list. To create an ACL, you must add at least one rule to the list.

To remove a rule, use the no permit or no deny command followed by the exact text of a previously configured rule.

44-12

Page 400
Image 400
Accton Technology ES4524D, ES4548D, 24/48-Port manual MAC ACLs, Access-list mac, MAC ACL Commands Function Mode, 44-13