MAC ACL Default Action
The default action when no ACLs are configured on a device is to permit all traffic. Once you apply a MAC ACL to a port or VLAN, the device drops all Ethernet traffic on the port or VLAN that does not match a MAC permit filter. Given these defaults, follow these guidelines for configuring and applying ACLs:
- If you want to tightly control access, configure MAC ACLs consisting of permit entries for the access you want to permit. The MAC ACLs implicitly deny all other access.
- If you want to secure access in environments with many users, you may want to configure MAC ACLs that consist of explicit deny entries and then add an entry to permit all access (for example, "permit any any") to the end of each MAC ACL so that the software permits all MAC addresses that do not match a previous deny statement.