Reference Guide
Version 7.6.1.0 Introduced on the S-Series.
Version 7.5.1.0 Introduced on the C-Series.
pre-Version 
6.1.1.0
Introduced on the E-Series.
Usage 
Information
The number of entries allowed per ACL is hardware-dependent. For detailed specifications on 
entries allowed per ACL, refer to your line card documentation.
Prior to 7.8.1.0, names are up to 16 characters long.
Example
FTOS(conf)#mac-access-list access-list extended TestMATExt
FTOS(config-ext-macl)#remark 5 IPv4
FTOS(config-ext-macl)#seq 10 permit any any ev2 eq 800 count 
bytes
FTOS(config-ext-macl)#remark 15 ARP
FTOS(config-ext-macl)#seq 20 permit any any ev2 eq 806 count 
bytes
FTOS(config-ext-macl)#remark 25 IPv6
FTOS(config-ext-macl)#seq 30 permit any any ev2 eq 86dd count 
bytes
FTOS(config-ext-macl)#seq 40 permit any any count bytes
FTOS(config-ext-macl)#exit
FTOS(conf)#do show mac accounting access-list snickers 
interface g0/47 in
Extended mac access-list snickers on GigabitEthernet 0/47
seq 10 permit any any ev2 eq 800 count bytes (559851886 
packets 191402152148
bytes)
seq 20 permit any any ev2 eq 806 count bytes (74481486 packets 
5031686754
bytes)
seq 30 permit any any ev2 eq 86dd count bytes (7751519 packets 
797843521 bytes)
Related 
Commands
mac access-list standard — configures a standard MAC access list.
show mac accounting access-list — displays MAC access list configurations and counters (if 
configured).
permit
To pass packets matching the criteria specified, configure a filter.
S4820T
Syntax
permit {any | host mac-address | mac-source-address mac-source-
address-mask} {any | host mac-address | mac-destination-address 
mac-destination-address-mask} [ethertype operator] [count 
[byte]] | [log] [monitor]
To remove this filter, you have two choices:
• Use the no seq sequence-number command if you know the filter’s sequence 
number.
• Use the no permit {any | host mac-address | mac-source-
address mac-source-address-mask} {any | mac-destination-
address mac-destination-address-mask} command.
226










