MAC ACLs

When upgrading from a previous major release to FastIron 08.0.95 or a later release, all the existing MAC filters and their bindings in the startup configuration are migrated to MAC ACLs.

MAC filters defined by the mac filter command in releases prior to FastIron 08.0.95 that are bound to a particular physical interface or LAG with the mac filter-group command are converted into MAC ACLs, which are configured from FastIron 08.0.95 using the mac access-list command. The mac access-list command allows permit and deny filter statements to be created in MAC ACL configuration mode. The filters in a MAC ACL will appear in the same order as defined in the MAC filters.

Note: Permit and deny statements for MAC ACLs have a syntax similar to IP ACLs. For more information, refer to the RUCKUS FastIron Command Reference Guide.

An existing MAC filter that is not in any binding group is translated and added into a default MAC ACL. The mac filter-group command, used for binding MAC filters on an interface and LAG in releases prior to FastIron 08.0.95, has been replaced with the mac access-group command. The mac access-group command binds MAC ACLs to a physical interface, LAG, VLAN, and so on. The MAC filter functionality remains intact after an upgrade. Beginning with FastIron 08.0.95, the mac filter and mac filter-group commands are deprecated.