HP 1606 Converged Enhanced Ethernet Command Reference v6.4.0 (53-1001762-01, J - Page 133

mac access-group, to remove the MAC ACL from the interface.

Page 133 highlights

DRAFT: BROCADE CONFIDENTIAL mac access-group 8 mac access-group Synopsis Operands Default Command Modes Description Usage Guidelines Example See Also Applies rules specified in a MAC ACL to traffic entering an interface. mac access-group name in no mac access-group name name in Specifies the name of the standard or extended MAC access list. Specifies to filter inbound packets only. There are no access lists applied to the interface. Interface configuration mode Use this command to apply a MAC ACL to a Layer 2 or a VLAN interface. You create the MAC ACL by using the mac access-list global configuration command. Use the no mac access-group command to remove the MAC ACL from the interface. You can assign one MAC ACL (standard or extended) to an interface. When a packet is received on an interface with a MAC ACL applied, the switch checks the rules in the ACL. If any of the rules match, the switch permits or drops the packet, according to the rule. If the specified ACL does not exist, the switch permits all the packets. To apply a MAC ACL named macacl2 on an interface: switch(conf-if)#mac access-group macacl2 in To remove a MAC ACL named macacl2 from an interface: switch(conf-if)#no mac access-group macacl2 mac access-list standard, mac access-list extended, show access-lists Converged Enhanced Ethernet Command Reference 115 53-1001762-01

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252

Converged Enhanced Ethernet Command Reference
115
53-1001762-01
mac access-group
8
DRAFT: BROCADE CONFIDENTIAL
mac access-group
Applies rules specified in a MAC ACL to traffic entering an interface.
Synopsis
mac access-group
name
in
no mac access-group
name
Operands
name
Specifies the name of the standard or extended MAC access list.
in
Specifies to filter inbound packets only.
Default
There are no access lists applied to the interface.
Command
Modes
Interface configuration mode
Description
Use this command to apply a MAC ACL to a Layer 2 or a VLAN interface. You create the MAC ACL by
using the
mac access-list
global configuration command. Use the
no mac access-group
command
to remove the MAC ACL from the interface.
Usage
Guidelines
You can assign one MAC ACL (standard or extended) to an interface.
When a packet is received on an interface with a MAC ACL applied, the switch checks the rules in
the ACL. If any of the rules match, the switch permits or drops the packet, according to the rule. If
the specified ACL does not exist, the switch permits all the packets.
Example
To apply a MAC ACL named macacl2 on an interface:
switch(conf-if)#
mac access-group macacl2 in
To remove a MAC ACL named macacl2 from an interface:
switch(conf-if)#
no mac access-group macacl2
See Also
mac access-list standard
,
mac access-list extended
,
show access-lists