Configuration Commands
Access Control configuration
Use these commands to create Access Control Lists (ACLs) and ACL Groups. ACLs define matching criteria used for IP filtering and Quality of Service functions.
Access Control List configuration
These commands allow you to define filtering criteria for each Access Control List (ACL). The following table describes the basic ACL Configuration commands.
Table 155 ACL Configuration commands
Command | Description | |
|
| |
[no] | Configures the ACL to function on egress packets. | |
384> | The egress port ACL will not match a Layer 2 broadcast or multicast | |
number> | ||
packet. The egress port ACL will not match packets if the destination port | ||
| ||
| is a trunk. | |
| Command mode: Global configuration | |
|
| |
Configures a filter action for packets that match the ACL definitions. You | ||
action {permitdenyset- | can choose to permit (pass) or deny (drop) packets, or set the Class of | |
priority | Service queue that handles the packets. | |
| ||
| Command mode: Global configuration | |
|
| |
Enables or disables the statistics collection for the Access Control List. | ||
statistics | Command mode: Global configuration | |
| ||
|
| |
default | Resets the ACL parameters to their default values. | |
| Command mode: Global configuration | |
| ||
|
| |
show | Displays the current ACL parameters. | |
384> | Command mode: All except User EXEC | |
| ||
|
|
ACL Ethernet Filter configuration
These commands allow you to define Ethernet matching criteria for an ACL. The following table describes the Ethernet Filter Configuration commands.
Table 156 Ethernet Filter Configuration commands
Command | Description |
|
|
Defines the source MAC address and MAC mask for this ACL. | |
For example: | |
{<MAC mask>} | 00:60:cf:40:56:00 ff:ff:ff:ff:ff:fc |
| |
| Command mode: Global configuration |
|
|
Defines the destination MAC address and MAC mask for this | |
ACL. For example: | |
{<MAC mask>} | 00:60:cf:40:56:00 ff:ff:ff:ff:ff:fc |
| |
| Command mode: Global configuration |
|
|
Defines a VLAN number and mask for this ACL. | |
vlan | Command mode: Global configuration |
| |
|
|
| 171 |