MAC ACL Configuration Notes and Limitations
Keep the following points in mind when configuring MAC ACLs:
- MAC ACL filtering on RUCKUS ICX devices is performed in hardware.
- On RUCKUS ICX devices, MAC ACLs can match on source and destination MAC addresses and Ethertype.
- MAC ACLs do not filter Layer 2 control protocols. Layer 2 control protocols, such as STP and LACP, are processed by the device even when a "deny any" statement is included in a MAC ACL and applied.
- MAC ACLs cannot be applied on the out-of-band management port.
- If you apply a MAC ACL to a port or VLAN that already has a MAC ACL applied, the older MAC ACL is replaced by the new ACL.
The following configuration notes apply to RUCKUS Layer 3 devices:
- MAC ACLs apply to both switched and routed traffic. If a routing protocol (for example, OSPF) is configured on an interface, the configuration must include a MAC ACL rule that allows the routing protocol MAC and the neighbor system MAC address.
- MAC ACLs are supported on tagged ports.
- MAC ACLs do not support filtering based on Layer 4 information.
- MAC ACL logging does not work in the following case: Ingress logging is enabled for IPv4, IPv6, and MAC ACLs for the same VLAN, interface, or selective port in a VLAN, and transmitted IPv4 or IPv6 traffic matches IPv4 or IPv6 ACL rules.