CLI Reference Guide-R07

Table Of Contents
Chapter 10
| Access Control Lists
MAC ACLs
– 347 –
access-list mac This command enters MAC ACL configuration mode. Rules can be added to filter
packets matching a specified MAC source or destination address (i.e., physical layer
address), or Ethernet protocol type. Rules can also be used to filter packets based
on IPv4/v6 addresses, including Layer 4 ports and protocol types. Use the no form
to remove the specified ACL.
Syntax
[no] access-list mac acl-name
acl-name – Name of the ACL. (Maximum length: 32 characters,)
Default Setting
None
Command Mode
Global Configuration
Command Usage
When you create a new ACL or enter configuration mode for an existing ACL,
use the permit or deny command to add new rules to the bottom of the list.
To remove a rule, use the no permit or no deny command followed by the
exact text of a previously configured rule.
An ACL can contain up to 128 rules.
Example
Console(config)#access-list mac jerry
Console(config-mac-acl)#
Related Commands
permit, deny (348)
mac access-group (350)
show mac access-list (351)
show mac access-group Shows port assignments for MAC ACLs PE
show mac access-list Displays the rules for configured MAC ACLs PE
Table 68: MAC ACL Commands (Continued)
Command Function Mode