Brocade Converged Enhanced Ethernet Administrator's Guide v6.1.2_cee (53-1001258-01, June 2009)

Table Of Contents
Converged Enhanced Ethernet Administrator’s Guide 99
53-1001258-01
ACL configuration procedures
7
Removing a MAC ACL
To remove a MAC ACL, perform the following steps from Privileged EXEC mode:
Reordering the sequence numbers in a MAC ACL
You can reorder the sequence numbers assigned to rules in a MAC ACL. Reordering the sequence
numbers is useful when you need to insert rules into an ACL and there are not enough available
sequence numbers.
To reorder the rules in a MAC ACL, perform the following task from Privileged EXEC mode:
Applying a MAC ACL to a CEE interface
Ensure that the ACL that you want to apply exists and is configured to filter traffic in the manner
that you need for this CEE interface. An ACL does not take effect until it is expressly applied to an
interface using the access-group command. Packets can be filtered as they enter an interface
(ingress direction).
To apply a MAC ACL to a CEE interface, perform the following steps from Privileged EXEC mode:
Step Task Command
1. Enter global configuration mode. switch#config t
Enter configuration commands, one per
line. End with CNTL/Z.
switch(config)#
2. Specify the ACL that you want to remove. In this
example, the extended MAC ACL name is
“test_02.
switch(config)#no mac access-list
extended test_02
switch(config)#
Task Command
Assign sequence numbers to the rules contained in the
MAC ACL. The first rule receives the number specified by
the starting-sequence number that you specify. Each
subsequent rule receives a number larger than the
preceding rule. The difference in numbers is determined
by the increment number that you specify. The
starting-sequence number and the increment number
must be in the range of 1 through 65535.
switch#resequence access-list mac
access-list_name
starting_sequence_number
increment_number
Step Task Command
1. Enter global configuration mode. switch#config t
Enter configuration commands, one per
line. End with CNTL/Z.
switch(config)#
2. Specify the CEE interface (interface 0/1 is used
in this example).
switch(config)#interface
tengigabitethernet 0/1
switch(conf-if-te-0/1)#
3. Configure the interface as a Layer 2 switch port. switch(conf-if-te-0/1)#switchport
4. Specify the MAC ACL that is to be applied to the
Layer 2 CEE interface in the ingress direction.
switch(conf-if-te-0/1)#mac
access-group access_list_name in