Manual
+7(495) 797-3311 www.qtech.ru 
Москва, Новозаводская ул., 18, стр. 1 
305 
Command 
Explanation 
Global Mode 
access-list<num> {deny|permit} {any-source-mac| 
{host-source-mac<host_smac>}|{<smac><smac-
mask>}}{any-destination-mac|{host-destination-
mac<host_dmac>}|{<dmac><dmac-mask>}}[untagged-
eth2 | tagged-eth2 | untagged-802-3 | tagged-802-3] 
no access-list <num> 
Creates  a  numbered  MAC 
extended  access-list,  if  the 
access-list already  exists, then 
a  rule  will  add  to  the  current 
access-list;  the  “no  access-list 
<num>“  command  deletes  a 
numbered  MAC  extended 
access-list. 
(7) Configuring a extended MAC access-list based on nomenclature 
1)  Create an extensive MAC access-list based on nomenclature 
Command 
Explanation 
Global Mode 
mac-access-list extended <name> 
no mac-access-list extended <name> 
Creates  an  extended  name-
based  MAC  access  rule  for 
other  IP  protocols;  the  no  form 
command  deletes  this  name-
based  extended  MAC  access 
rule. 
2)  Specify multiple “permit” or “deny” rule entries 
Command 
Explanation 
Extended name-based MAC access rule Mode 
[no]{deny|permit}{any-source-mac|{host-source-
mac<host_smac>}|{<smac><smac-mask>}} {any-
destination-mac|{host-destination-mac <host_dmac>} 
|{<dmac> <dmac-mask>}} [cos <cos-val> [<cos-
bitmask>] [vlanId <vid-value> [<vid-
mask>][ethertype<protocol>[<protocol-mask>]]]] 
Creates  an  extended  name-
based  MAC  access  rule 
matching  MAC  frame;  the  no 
form  command  deletes  this 
name-based  extended  MAC 
access rule. 
[no]{deny|permit}{any-source-mac|{host-source-
mac<host_smac>}|{<smac><smac-mask>}}{any-
destination-mac|{host-destination-
mac<host_dmac>}|{<dmac><dmac-mask>}}[untagged-
eth2 [ethertype <protocol> [protocol-mask]]] 
Creates  an  extended  name-
based  MAC  access  rule 
matching  untagged  ethernet  2 
frame;  the  no  form  command 
deletes  this  name-based 










