mac access-group (ACL)

Binds an access-list filter to an interface.
Syntax
mac access-group { name in } [ logging enable ]
no mac access-group { name in } [ logging enable ]
Parameters
name
MAC ACL name
in
Indicates that the MAC ACL is to be applied to inbound traffic.
Modes

Interface configuration mode

Usage Guidelines

The no form of the command unbinds the MAC ACL from the interface.

The logging enable option included in a mac access-group bind allows logging of any matched statement within the applied mac access-list that contains a log action.

Examples

The following example binds the MAC ACL named mac123 to an interface.

device# configure terminal
device(config)# interface ethernet 1/1/2
device(config-if-e1000/1/1/2)# mac access-group mac123 in

The following example unbinds MAC ACL mac123 from the interface.

device# configure terminal
device(config)# interface ethernet 1/1/2
device(config-if-e1000/1/1/2)# no mac access-group mac123 in

The following example creates a mac access-list and applies it to a lag interface with logging turned on.

device# configure terminal
device(config)# mac access-list mac
device(config-macl-mac)# enable accounting
device(config-macl-mac)# deny any 0000.0000.0088 0000.0000.1111 log
device(config-macl-mac)# permit any any log
device(config-macl-mac)# interface lag 46
device(config-lag-if-lg46)# mac access-group mac in logging enable
device(config-lag-if-lg46)# exit
device(config)#
History
Release version Command history
08.0.95 This command was introduced.