Configuring and Applying MAC ACLs
Complete the following steps to configure and apply a MAC ACL.
- Enter global configuration mode.
- Enter the
mac access-listcommand followed by a unique ACL name to enter MAC ACL configuration sub-mode. Define the set of MAC ACL filter statements to permit or deny traffic based on source and/or destination MAC address and optional Ethertype.In the source or destination MAC address field, you can specify a particular MAC address with an exact mask or a range of MAC addresses with a variable mask, or you can specify any to match any MAC address. Specify the mask using hexadecimal numbers 0 through f. For example, to match on the first two bytes of the address 0010.0075.3676, use the mask ffff.0000.0000. In this case, the filter matches on all MAC addresses that contain "0010" as the first two bytes. The filter accepts any value for the remaining bytes of the MAC address.
device(config)# mac access-list mac01 device(config-macl-mac01)# deny any 0010.0075.3676 ffff.0000.0000 device(config-macl-mac01)# deny any 0000.0023.fbcd ffff.ffff.ffff device(config-macl-mac01)# deny 0000.0123.0121 ffff.ffff.fff5 any device(config-macl-mac01)# deny any 0180.c200.0000 ffff.ffff.ffff device(config-macl-mac01)# deny any 0000.0034.5678 ffff.ffff.ffff device(config-macl-mac01)# deny any 0000.0045.6789 ffff.ffff.ffff device(config-macl-mac01)# permit any any
The previous example contains five deny statements and permits traffic from any other source or destination address. The first deny statement denies all source MAC addresses that begin with 0010. The third deny statement denies traffic to any destination address when the source address matches values in the range 0000.0123.0126 through 0000.0123.012f (values 0120 through 0125 are allowed in the last byte). The remaining deny statements deny any source MAC address sent to a specific MAC address. - To apply a previously created
MAC ACL, enter interface configuration sub-mode and enter the
mac access-groupcommand followed by the name of the MAC ACL and the in keyword. This applies the MAC ACL to all inbound traffic.The previous example applies the MAC ACL created in this task to inbound traffic on port 1/1/1.When a MAC ACL is applied to or removed from an interface, a syslog message is generated.
SYSLOG: <14> May 7 16:22:03 ACL: acl1 applied to eth 1/1/1 by un-authenticated user from console session.
SYSLOG: <14> May 7 16:22:43 ACL: acl1 removed from eth 1/1/1 by un-authenticated user from console session.
The syslog messages indicate that a MAC ACL was applied to the specified port and then removed by an unauthenticated user during the specified session type. The session type can be Console, Telnet, SSH, Web, or SNMP, among others.
Note: A MAC ACL can be applied to a port, LAG, VLAN, or selected ports of a VLAN.
The following example denies Layer 2 traffic if the conditions of the MAC ACL deny statements are matched and permits traffic from all other source MAC addresses as per the last match statement. The MAC ACL is applied to inbound traffic on port 1/1/2.
device# configure terminal device(config)# mac access-list mac02 device(config-macl-mac02)# deny 0010.0075.3676 ffff.0000.0000 device(config-macl-mac02)# deny any 0000.0023.fbcd ffff.ffff.ffff device(config-macl-mac02)# deny any 0180.c200.0000 ffff.ffff.fff0 device(config-macl-mac02)# deny any 0000.0034.5678 ffff.ffff.ffff device(config-macl-mac02)# deny any 0000.0045.6789 ffff.ffff.ffff device(config-macl-mac02)# permit any any device(config-macl-mac02)# interface ethernet 1/1/2 device(config-if-e1000-1/1/2)# mac access-group mac02 in
The following example defines an ACL that allows all traffic from a specific Ethertype, in this case, 0800, or IPv4.
device# configure terminal device(config)# mac access-list mac21 device(config-macl-mac21)# permit any any ether-type 0800
The following example creates MAC ACL mac02, which denies traffic from a specific MAC address to another specific MAC address and permits all other traffic. It applies the MAC ACL to inbound traffic on LAG 46.
device# configure terminal device(config)# mac access-list mac02 device(config-macl-mac02)# deny any 0000.0000.0088 0000.0000.1111 device(config-macl-mac02)# permit any any device(config-macl-mac02)# interface lag 46 device(config-lag-if-lg46)# mac access-group mac02 in device(config-lag-if-lg46)# exit device(config)#
The following example applies a previously created MAC ACL to inbound traffic in a VLAN.
device# configure terminal device(config)# vlan 555 by port device(config-vlan-555)# tagged ethernet 1/2/2 lag 10 device(config-vlan-555)# interface ve 555 device(config-vlan-555)# mac access-group mac02 in device(config-vlan-555)# exit device(config)#
The following example applies the same MAC ACL to inbound traffic on selected ports (port 1/1/21 and LAG 5 ports) in VLAN 41.
device# configure terminal device(config)# vlan 41 by port device(config-vlan-41)# tagged ethernet 1/1/21 lag 5 device(config-vlan-41)# mac access-group mac02 in ethernet 1/1/21 lag 5 device(config-vlan-41)# exit device(config)#