Displaying MAC ACL Information

Use the following commands to display information about MAC ACLs:

  • show mac access-lists
  • show running-config access-list

Note: Refer to Displaying TCAM Information for ACLs for information on MAC ACL TCAM usage.

Use the show mac access-lists brief command for a summary of information about all configured MAC ACLs.

device# show mac access-lists brief 

 Total ACL count= 2     
 Total ACL filter count= 10    

 ACL Name                             Filters  Bindings(In)   Bindings(Out)  Acc

 ===================================  =======  =============  =============  ===
 mac_acl                              10       0              0              dis
 vlan22                               0        1              0              dis

Use the show mac access-lists command to display information for all configured MAC ACLs.

device# show mac access-lists
mac access-list mac123: 1 entries
permit 1111.2222.3333 ffff.ffff.ffff 4444.5555.6666 ffff.ffff.ffff
mac access-list mac456: 1 entries
permit 1234.5678.9000 ffff.ffff.ffff any

Use the show mac access-lists command followed by a MAC ACL name to display information for a specific MAC ACL.

device# show mac access-lists mac456
mac access-list mac456: 1 entries
permit 1234.5678.9000 ffff.ffff.ffff any log mirror

Use the show mac access-lists bindings command to display information about where specific MAC ACLs are applied. The command can be entered for a particular MAC ACL, LAG, or interface.

device(config)# show mac access-lists bindings
ACL Name                             Bind If                Dir  
===================================  =====================  === 
acl1                                 eth 1/1/1              in  
acl1                                 lag 1                  in 
ICX7450-48P Router(config)#

The following example displays the filter statements for configured MAC ACLs.

device(config-vlan-333)# show running-config access-list mac
!
mac access-list mac_acl
 permit 0000.0000.1111 ffff.ffff.ffff any log  
 permit 0000.0000.4444 ffff.ffff.ffff any log  
 permit 0000.0000.5555 ffff.ffff.ffff any log  
 permit 0000.0000.6666 ffff.ffff.ffff any log  
 permit 0000.0000.7777 ffff.ffff.ffff any log  
 permit 0000.0000.8888 ffff.ffff.ffff any log  
 permit 0000.0000.9999 ffff.ffff.ffff any log  
 permit 0000.0009.1010 ffff.ffff.ffff any log  
 permit 0000.0009.1011 ffff.ffff.ffff any log  
 permit any any log  
mac access-list vlan22
!
device(config-vlan-333)#