ACL configuration and management

10

Applying a MAC ACL to a CEE interface

Ensure that the ACL that you want to apply exists and is configured to filter traffic in the manner that you need for this CEE interface. An ACL does not take effect until it is expressly applied to an interface using the access-groupcommand. Frames can be filtered as they enter an interface (ingress direction).

To apply a MAC ACL to a CEE interface, perform the following steps from privileged EXEC mode.

1.Enter the configure terminal command to access global configuration mode.

2.Enter the interface command to specify the CEE interface type and slot/port number.

switch(config)#interface tengigabitethernet 0/1

3.Enter the switchport command to configure the interface as a Layer 2 switch port.

4.Enter the mac-access-groupcommand to specify the MAC ACL that is to be applied to the Layer 2 CEE interface in the ingress direction.

switch(conf-if-te-0/1)#mac access-group test_02 in

Applying a MAC ACL to a VLAN interface

Ensure that the ACL that you want to apply exists and is configured to filter traffic in the manner that you need for this VLAN interface. An ACL does not take effect until it is expressly applied to an interface using the access-groupcommand. Frames can be filtered as they enter an interface (ingress direction).

To apply a MAC ACL to a VLAN interface, perform the following steps from privileged EXEC mode.

1.Enter the configure terminal command to access global configuration mode.

2.Enter the interface command to apply the VLAN interface to the MAC ACL.

switch(config)#interface vlan 50

3.Enter the mac-access-groupcommand to specify the MAC ACL that is to be applied to the VLAN interface in the ingress direction.

switch(conf-if-vl-82)# mac access-group test_02 in

Converged Enhanced Ethernet Administrator’s Guide

105

53-1002163-02

 

Page 127
Image 127
Brocade Communications Systems 53-1002163-02 Applying a MAC ACL to a CEE interface, Applying a MAC ACL to a Vlan interface