mac access-list

Creates Layer 2 access list.
Syntax
mac access-list { name }
no mac access-list { name }
Parameters
name
Name of the MAC ACL to be applied.
Modes

Global configuration mode

Usage Guidelines

The no form of the command deletes the ACL.

The syntax for creating MAC ACL filters in MAC ACL configuration sub-mode is as follows:

device(config-macl-name)# permit | deny { { source_mac_address [ source_mask ] } | any } { destination_mac_address [ destination_mask ] } | any } [ ether-type ether_type_value ] [ log ] [ mirror ]

The log option can be added to a MAC ACL and must be enabled with the logging enable option for ingress traffic as part of a mac access-group command.

The mirroring option that can be specified as part of the filter definition must be used in conjunction with the acl-mirror-port command configured for the interface on which the MAC ACL is bound. The mirroring option can be disabled only by the no acl-mirror-port command entered for the same interface. Refer to the RUCKUS FastIron Monitoring Configuration Guide for more information on mirroring.

Valid Ethertype values for MAC ACLs are in the range 600 through ffff.

Examples

The following example deletes the MAC ACL mac123.

device# configure terminal
device(config)# no mac access-list mac123

The following example creates the MAC ACL mac123 and adds filters to be applied globally at Layer 2. The first action for source MAC (1111.222.3333) allows traffic from destination MAC address 4444.5555.6666. The second action for source MAC address 1234.5678.9000 allows traffic from any destination MAC address. The more restricted set of destination addresses allowed must be placed first, with the any statement placed last for the filters to work as planned.

device# configure terminal
device(config)# mac access-list mac123
device(config-macl-mac123)# permit 1111.2222.3333 ffff.ffff.ffff 4444.5555.6666 ffff.ffff.ffff
device(config-macl-mac123)# permit 1234.5678.9000 ffff.ffff.ffff any
device(config-macl-mac123)# exit
device(config)#

The following example allows any source MAC address to send traffic with an Ether-type qualifier of 0x0800 to any destination MAC address.

device# configure terminal
device(config)# mac access-list mac456
device(config-macl-mac456)# permit any any ether-type 0800

The following example removes the first action line from the MAC access-list mac123.

device# configure terminal
device(config)# mac access-list mac123
device(config-macl-mac123)# no permit 1111.2222.3333 ffff.ffff.ffff 4444.5555.6666 ffff.ffff.ffff

The following example allows statistics to be collected on the MAC ACL. The ACL denies all traffic from a specific set of IP addresses and permits all other traffic. All traffic matching the deny statement or the permit statement creates a log entry for LAG interface 46 because logging is enabled as part of applying the MAC ACL to the LAG with the mac access-group command.

device# configure terminal
device(config)# mac access-list maclog
device(config-macl-maclog)# enable accounting
device(config-macl-maclog)# deny any 0000.0000.0088 0000.0000.1111 log
device(config-macl-maclog)# permit any any log
device(config-macl-maclog)# interface lag 46
device(config-lag-if-lg46)# mac access-group maclog in logging enable
device(config-lag-if-lg46)# exit
device(config)#

History
Release version Command history
08.0.95 This command was introduced.