[no] {permit | den y} untagged-802.3
{any | host source | source address-bitmask}
{
any
|
host
destination | destination address-bitmask}
tagged-eth2 – Tagged Ethernet II packets.
untagged-eth2 – Untagg ed Ether net II packe ts.
tagged-802.3 – Tagged Eth ernet 80 2.3 packe ts.
untagged-802.3 – Un tagge d Ethernet 8 02.3 pack ets.
any – Any MAC source or destination address.
host – A specific MAC address.
source – Source MAC address.
destination – Destination MAC address range with bitmas k.
address-bitmask27 – Bitmask for M AC addres s (in hexidec imal form at).
vid – VLAN ID. (Range: 1-4093)
vid-bitmask27VLAN bitmask. (Range: 1- 4093)
protocol – A specific Ethernet protocol number. (R ange: 600-f ff hex.)
protocol-bitmask
27
– Protocol bitmask. (Range: 600-fff hex.)
Default Setting
None
Command Mode
MAC ACL
Command Usage
New rules are added to the end of the list.
• The
ethertype
option can only be used to filter Ethernet II formatted packets .
A detailed listing of Ethernet pr otoc ol type s c an be found in RFC 1060. A fe w
of the more common types include the following:
- 0800 - IP
- 0806 - ARP
- 8137 - IPX
Example
This rule permits packets from any source MAC address to th e destin ation address
00-e0-29-94-34-de where the Ethernet type is 0800.
Console(config-mac-acl)#permit any host 00-e0-29-94-34-de ethertype 0800
Console(config-mac-acl)#
Related Commands
access-list mac (26-12)
27. For all bitmasks, “1” means care and “0” means ignore.
26-14
Access Control List Commands
26