TP-Link TL-SG5428 TL-SG5428 V1 CLI Reference Guide - Page 151

acl rule mac-acl

Page 151 highlights

be Standard-IP ACL, and 200-299 must be Extend-IP ACL. Command Mode Global Configuration Mode Example Create a MAC ACL whose ID is 20: TP-LINK(config)# acl create 20 acl rule mac-acl Description The acl rule mac-acl command is used to add MAC ACL rule. To delete the corresponding rule, please use no acl rule mac-acl command. MAC ACLs analyze and process packets based on a series of match conditions, which can be the source MAC addresses, destination MAC addresses, VLAN ID, and EtherType carried in the packets. Syntax acl rule mac-acl {acl-id} {rule-id} [op {discard | permit }] [[smac source-mac] {smask source-mac-mask}] [[dmac destination-mac] {dmask destination-mac-mask}] [vid vlan-id] [type Ethernet-type] [pri user-pri] [tseg time-segment] no acl rule mac-acl {acl-id} {rule-id} Parameter acl-id -- The desired MAC ACL for configuration. rule-id -- The rule ID. op -- The operation for the switch to process packets which match the rules. There are two options, discard and permit. Discard means discarding packets, and permit means forwarding packets. By default, the option is permit. source-mac -- The source MAC address contained in the rule. source-mac-mask -- The source MAC address mask. It is required if you typed the source MAC address. destination-mac -- The destination MAC address contained in the rule. destination-mac-mask -- The destination MAC address mask. It is required if you typed the destination MAC address. vlan-id -- The VLAN ID contained in the rule, ranging from 1 to 4094. Ethernet-type -- EtherType contained in the rule, in the format of 4-hex 139

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216

139
be Standard-IP ACL, and 200-299 must be Extend-IP ACL.
Command Mode
Global Configuration Mode
Example
Create a MAC ACL whose ID is 20:
TP-LINK(config)# acl create
20
acl rule mac-acl
Description
The
acl rule mac-acl
command is used to add MAC ACL rule. To delete the
corresponding rule, please use
no acl rule mac-acl
command. MAC ACLs
analyze and process packets based on a series of match conditions, which can
be the source MAC addresses, destination MAC addresses, VLAN ID, and
EtherType carried in the packets.
Syntax
acl rule mac-acl
{
acl-id
} {
rule-id
} [
op
{discard | permit }] [[
smac
source-mac
]
{
smask
source-mac-mask
}] [[
dmac
destination-mac
] {
dmask
destination-mac-mask
}] [
vid
vlan-id
] [
type
Ethernet-type
] [
pri
user-pri
] [
tseg
time-segment
]
no acl rule mac-acl
{
acl-id
} {
rule-id
}
Parameter
acl-id
—— The desired MAC ACL for configuration.
rule-id
—— The rule ID.
op —— The operation for the switch to process packets which match the rules.
There are two options, discard and permit. Discard means discarding packets,
and permit means forwarding packets. By default, the option is permit.
source-mac
—— The source MAC address contained in the rule.
source-mac-mask
—— The source MAC address mask. It is required if you
typed the source MAC address.
destination-mac
—— The destination MAC address contained in the rule.
destination-mac-mask
—— The destination MAC address mask. It is required if
you typed the destination MAC address.
vlan-id
—— The VLAN ID contained in the rule, ranging from 1 to 4094.
Ethernet-type
—— EtherType contained in the rule, in the format of 4-hex