44 Access Control List Commands

source – Source MAC address.

destination – Destination MAC address range with bitmask.

address-bitmask2– Bitmask for MAC address (in hexidecimal format).

vid – VLAN ID. (Range: 1-4093)

vid-bitmask2VLAN bitmask. (Range: 1-4093)

protocol – A specific Ethernet protocol number. (Range: 600-fff hex.)

protocol-bitmask2– Protocol bitmask. (Range: 600-fff hex.)

Default Setting

None

Command Mode

MAC ACL

Command Usage

New rules are added to the end of the list.

The ethertype option can only be used to filter Ethernet II formatted packets.

A detailed listing of Ethernet protocol types can be found in RFC 1060. A few of the more common types include the following:

-0800 - IP

-0806 - ARP

-8137 - IPX

Example

This rule permits packets from any source MAC address to the destination address 00-e0-29-94-34-de where the Ethernet type is 0800.

Console(config-mac-acl)#permit any host 00-e0-29-94-34-de ethertype 0800 Console(config-mac-acl)#

Related Commands

access-list mac (44-12)

show mac access-list

This command displays the rules for configured MAC ACLs.

Syntax

show mac access-list [acl_name]

acl_name – Name of the ACL. (Maximum length: 16 characters)

Command Mode

Privileged Exec

2. For all bitmasks, “1” means care and “0” means ignore.

44-14

Page 402
Image 402
Accton Technology ES4548D, ES4524D manual Show mac access-list, This command displays the rules for configured MAC ACLs