Configuration Guide (Supporting R2.2.0.0) Owner's manual

Brocade 6910 Ethernet Access Switch Configuration Guide 245
53-1002651-02
11
MAC ACLs
Console#
Related Commands
“ipv6 access-group” on page 244
MAC ACLs
The commands in this section configure ACLs based on hardware addresses, packet format, and
Ethernet type. To configure MAC ACLs, first create an access list containing the required permit or
deny rules, and then bind the access list to one or more ports.
access-list mac
This command adds a MAC access list and enters MAC ACL configuration mode. Use the no form to
remove the specified ACL.
Syntax
[no] access-list mac acl-name
acl-name – Name of the ACL. (Maximum length: 16 characters, no spaces or other special
characters)
Default Setting
None
Command Mode
Global Configuration
Command Usage
When you create a new ACL or enter configuration mode for an existing ACL, use the permit or
deny command to add new rules to the bottom of the list.
To remove a rule, use the no permit or no deny command followed by the exact text of a
previously configured rule.
An ACL can contain up to 128 rules.
Example
Console(config)#access-list mac jerry
Console(config-mac-acl)#
TABLE 60 MAC ACL Commands
Command Function Mode
access-list mac Creates a MAC ACL and enters configuration mode GC
permit, deny Filters packets matching a specified source and destination address,
packet format, and Ethernet type
MAC-ACL
mac access-group Binds a MAC ACL to a port IC
show mac access-group Shows port assignments for MAC ACLs PE
show mac access-list Displays the rules for configured MAC ACLs PE