Access Control List Commands

4-151

4
[no]
{
permit
|
deny
}
untagged-eth2
{
any
|
host
source | source address-bitmask}
{
any
|
host
destination | destination address-bitmask}
[
ethertype
protocol [protocol-bitmask]]
[no]
{
permit
|
deny
}
tagged-802.3
{
any
|
host
source | source address-bitmask}
{
any
|
host
destination | destination address-bitmask}
[
vid
vid vid-bitmask]
[no]
{
permit
|
deny
}
untagged-802.3
{
any
|
host
source | source address-bitmask}
{
any
|
host
destination | destination address-bitmask}
tagged-eth2 – Tagged Ethernet II packets.
untagged-eth2 – Untagged Ethernet II packets.
tagged-802.3 – Tagged Ethernet 802.3 packets.
untagged-802.3 – Untagged Ethernet 802.3 packets.
any – Any MAC source or destination address.
host – A specific MAC address.
source – Source MAC address.
destination – Destination MAC address range with bitmask.
address-
bitmask
23 – Bitmask for MAC address (in hexidecimal format).
vid – VLAN ID. (Range: 1-4094)
vid-bitmask –
VLAN bitmask. (Range: 1-4094)
protocol – A specific Ethernet protocol number. (Range: 600-fff hex.)
protocol-bitmask – Protocol bitmask. (
Range: 600-fff hex.
)
Default Setting
None
Command Mode
MAC ACL
Command Usage
New rules are added to the end of the list.
The ethertype option can only be used to filter Ethernet II formatted packets.
A detailed listing of Ethernet protocol types can be found in RFC 1060. A few
of the more common types include the following:
- 0800 - IP
- 0806 - ARP
- 8137 - IPX
23. For all bitmasks, “1” means care and “0” means ignore.