Layer 2 ACL Overview

Note: MAC ACLs replaced separate MAC filter statements in FastIron release 08.0.95. Refer to the RUCKUS FastIron Software Upgrade Guide for additional information on the changes.

MAC ACLs are implemented much like IP ACLs using the following steps:

  1. Create the MAC ACL using the mac access-list command.
  2. Define permit and deny rules using the deny and permit commands.
  3. Apply the MAC ACL to one or more interfaces or VLANs using the mac access-group command.

MAC ACLs are supported on all ICX device physical interface types and LAGs.

MAC ACLs are named ACLs. Names must begin with an alphabetical character and contain no more than 47 characters.

MAC ACLs can be applied to individual interfaces, sets of interfaces, LAGs, VLANs, and selected ports within a VLAN and can be combined with IPv4 and IPv6 ACLs.

Note: For information on Layer 3 filtering as well as on configuring ACLs for LAGs and VLANs, enabling logging, enabling accounting, modifying ACL statements, and displaying information about TCAM usage, refer to ACLs.

Note: For the use of ACLs under Flexible Authentication, refer to Dynamic ACLs in Authentication.