Configuring and Applying MAC ACLs

Complete the following steps to configure and apply a MAC ACL.

  1. Enter global configuration mode.
    device# configure terminal
    device(config)#
  2. Enter the mac access-list command followed by a unique ACL name to enter MAC ACL configuration sub-mode. Define the set of MAC ACL filter statements to permit or deny traffic based on source and/or destination MAC address and optional Ethertype.

    In the source or destination MAC address field, you can specify a particular MAC address with an exact mask or a range of MAC addresses with a variable mask, or you can specify any to match any MAC address. Specify the mask using hexidecimal numbers 0 through f. For example, to match on the first two bytes of the address 0010.0075.3676, use the mask ffff.0000.0000. In this case, the filter matches on all MAC addresses that contain "0010" as the first two bytes. The filter accepts any value for the remaining bytes of the MAC address.

    device(config)# mac access-list mac01
    device(config-macl-mac01)# deny any 0010.0075.3676 ffff.0000.0000
    device(config-macl-mac01)# deny any 0000.0023.fbcd ffff.ffff.ffff
    device(config-macl-mac01)# deny 0000.0123.0121 ffff.ffff.fff5 any
    device(config-macl-mac01)# deny any 0180.c200.0000 ffff.ffff.ffff 
    device(config-macl-mac01)# deny any 0000.0034.5678 ffff.ffff.ffff 
    device(config-macl-mac01)# deny any 0000.0045.6789 ffff.ffff.ffff 
    device(config-macl-mac01)# permit any any
    
    The previous example contains five deny statements and permits traffic from any other source or destination address. The first deny statement denies all source MAC addresses that begin with 0010. The third deny statement denies traffic to any destination address when the source address matches values in the range 0000.0123.0126 through 0000.0123.012f (values 0120 through 0125 are allowed in the last byte). The remaining deny statements deny any source MAC address sent to a specific MAC address.
  3. To apply a previously created MAC ACL, enter interface configuration sub-mode and enter the mac access-group command followed by the name of the MAC ACL and the in keyword. This applies the MAC ACL to all inbound traffic.
    device(config)# interface ethernet 1/1/1
    device(config-if-e1000-1/1/1)# mac access-group mac01 in
    
    The previous example applies the MAC ACL created in this task to inbound traffic on port 1/1/1.

    When a MAC ACL is applied to or removed from an interface, a syslog message is generated.

    SYSLOG: <14> May  7 16:22:03 ACL: acl1 applied to eth 1/1/1 by un-authenticated user from console session.
    SYSLOG: <14> May  7 16:22:43 ACL: acl1 removed from eth 1/1/1 by un-authenticated user from console session.

    The syslog messages indicate that a MAC ACL was applied to the specified port and then removed by an unauthenticated user during the specified session type. The session type can be Console, Telnet, SSH, Web, or SNMP, among others.

    Note: A MAC ACL can be applied to a port, LAG, VLAN, or selected ports of a VLAN.

The following example denies Layer 2 traffic if the conditions of the MAC ACL deny statements are matched and permits traffic from all other source MAC addresses as per the last match statement. The MAC ACL is applied to inbound traffic on port 1/1/2.

device# configure terminal
device(config)# mac access-list mac02
device(config-macl-mac02)# deny 0010.0075.3676 ffff.0000.0000
device(config-macl-mac02)# deny any 0000.0023.fbcd ffff.ffff.ffff 
device(config-macl-mac02)# deny any 0180.c200.0000 ffff.ffff.fff0 
device(config-macl-mac02)# deny any 0000.0034.5678 ffff.ffff.ffff 
device(config-macl-mac02)# deny any 0000.0045.6789 ffff.ffff.ffff 
device(config-macl-mac02)# permit any any
device(config-macl-mac02)# interface ethernet 1/1/2
device(config-if-e1000-1/1/2)# mac access-group mac02 in

The following example defines an ACL that allows all traffic from a specific Ethertype, in this case, 0800, or IPv4.

device# configure terminal
device(config)# mac access-list mac21
device(config-macl-mac21)# permit any any ether-type 0800
Note: Valid Ethertype values for MAC ACLs are in the range 600 through ffff.

The following example creates MAC ACL mac02, which denies traffic from a specific MAC address to another specific MAC address and permits all other traffic. It applies the MAC ACL to inbound traffic on LAG 46.

device# configure terminal
device(config)# mac access-list mac02
device(config-macl-mac02)# deny any 0000.0000.0088 0000.0000.1111
device(config-macl-mac02)# permit any any
device(config-macl-mac02)# interface lag 46
device(config-lag-if-lg46)# mac access-group mac02 in
device(config-lag-if-lg46)# exit
device(config)#

The following example applies a previously created MAC ACL to inbound traffic in a VLAN.

device# configure terminal
device(config)# vlan 555 by port
device(config-vlan-555)# tagged ethernet 1/2/2 lag 10
device(config-vlan-555)# router-interface ve 555
device(config-vlan-555)# mac access-group mac02 in
device(config-vlan-555)# exit
device(config)#

The following example applies the same MAC ACL to inbound traffic on selected ports (port 1/1/21 and LAG 5 ports) in VLAN 41.

device# configure terminal
device(config)# vlan 41 by port
device(config-vlan-41)# tagged ethernet 1/1/21 lag 5
device(config-vlan-41)# mac access-group mac02 in ethernet 1/1/21 lag 5
device(config-vlan-41)# exit
device(config)#