MAC ACL Configuration Notes and Limitations

Keep the following points in mind when configuring MAC ACLs:

  • By default on RUCKUS ICX devices, 30 entries are reserved in the Layer 2 MAC ACL ingress group. However, on RUCKUS ICX 8100 and ICX 8200 devices, 31 entries are reserved.
    Is there a total of 30 entries or 31 entries for ICX 8100?31
  • MAC ACL filtering on RUCKUS ICX devices is performed in hardware.
  • On RUCKUS ICX devices, MAC ACLs can match on source and destination MAC addresses and Ethertype.
  • MAC ACLs do not filter Layer 2 control protocols. Layer 2 control protocols, such as STP and LACP, are processed by the device even when a "deny any" statement is included in a MAC ACL and applied.
  • MAC ACLs cannot be applied on the out-of-band management port.
  • If you apply a MAC ACL to a port or VLAN that already has a MAC ACL applied, the older MAC ACL is replaced by the new ACL.
  • MAC ACLs apply to both switched and routed traffic. If a routing protocol (for example, OSPF) is configured on an interface, the configuration must include a MAC ACL rule that allows the routing protocol MAC and the neighbor system MAC address.
  • MAC ACLs are supported on tagged ports.
  • MAC ACLs do not support filtering based on Layer 4 information.
  • MAC ACL logging does not work in the following case: Ingress logging is enabled for IPv4, IPv6, and MAC ACLs for the same VLAN, interface, or selective port in a VLAN, and transmitted IPv4 or IPv6 traffic matches IPv4 or IPv6 ACL rules.