Traffic/Security Filters and Monitors

Configuring Traffic/Security Filters

Figure 11-15. Assigning Additional Destination Ports to an Existing FilterConfiguring a Multicast or Protocol Traffic Filter

Syntax: [no] filter

[multicast < mac- address >]

Specifies a multicast address. Inbound traffic received (on any port) with this multicast address will be filtered. (Default: Forward on all ports.)

The no form of the command deletes the multicast filter for the < mac-address > multicast address and returns the destination ports for that filter to the Forward action.

[< forward drop > < port-list>]

Specifies whether the designated destination port(s) should forward or drop the filtered traffic.

[protocol < ip ipx arp appletalk sna netbeui >]

Specifies a protocol type. Traffic received (on any port) with this protocol type will be filtered. (Default: Forward on all ports.)

The no form of the command deletes the protocol filter for the specified protocol and returns the destination ports for that filter to the Forward action.

[< forward drop > < port-list>]

Specifies whether the designated destination port(s) should forward or drop the filtered traffic.

11-21