mac access-list
Global configuration mode
The
no
form of the command deletes the ACL.
The syntax for creating MAC ACL filters in MAC ACL configuration sub-mode is as follows:
device(config-macl-name)# permit | deny { { source_mac_address [ source_mask ] } | any } { destination_mac_address [ destination_mask ] } | any } [ ether-type ether_type_value ] [ log ] [ mirror ]
The
log option can be added to a MAC ACL and must be enabled with the
logging enable option for ingress traffic as part of a
mac access-group command.
The mirroring option that can be specified as part of the filter definition must be
used in conjunction with the
acl-mirror-port command configured for the interface on which the MAC ACL is bound. The mirroring
option can be disabled only by the
no acl-mirror-port command entered for the same interface. Refer to the
RUCKUS FastIron Monitoring Configuration Guide for more information on mirroring.
Valid Ethertype values for MAC ACLs are in the range 600 through ffff.
The following example deletes the MAC ACL mac123.
device# configure terminal device(config)# no mac access-list mac123
The following example creates the MAC ACL mac123 and adds filters to be applied globally at Layer 2. The first action for source MAC (1111.222.3333) allows traffic from destination MAC address 4444.5555.6666. The second action for source MAC address 1234.5678.9000 allows traffic from any destination MAC address. The more restricted set of destination addresses allowed must be placed first, with the any statement placed last for the filters to work as planned.
device# configure terminal device(config)# mac access-list mac123 device(config-macl-mac123)# permit 1111.2222.3333 ffff.ffff.ffff 4444.5555.6666 ffff.ffff.ffff device(config-macl-mac123)# permit 1234.5678.9000 ffff.ffff.ffff any device(config-macl-mac123)# exit device(config)#
The following example allows any source MAC address to send traffic with an Ether-type qualifier of 0x0800 to any destination MAC address.
device# configure terminal device(config)# mac access-list mac456 device(config-macl-mac456)# permit any any ether-type 0800
The following example removes the first action line from the MAC access-list mac123.
device# configure terminal device(config)# mac access-list mac123 device(config-macl-mac123)# no permit 1111.2222.3333 ffff.ffff.ffff 4444.5555.6666 ffff.ffff.ffff
The following example allows statistics to be collected on the MAC ACL. The ACL denies
all traffic from a specific set of IP addresses and permits all other traffic. All
traffic matching the deny statement or the permit statement creates a log entry for
LAG interface 46 because logging is enabled as part of applying the MAC ACL to the
LAG with the
mac access-group command.
device# configure terminal device(config)# mac access-list maclog device(config-macl-maclog)# enable accounting device(config-macl-maclog)# deny any 0000.0000.0088 0000.0000.1111 log device(config-macl-maclog)# permit any any log device(config-macl-maclog)# interface lag 46 device(config-lag-if-lg46)# mac access-group maclog in logging enable device(config-lag-if-lg46)# exit device(config)#
| Release version | Command history |
|---|---|
| 08.0.95 | This command was introduced. |