Yamaha 10G SWR2310-28GT/18GT/10G Command Reference - Page 235

Initial value], Input mode], Description], Note], Example], Syntax], access-group, Parameter],

Page 235 highlights

Command Reference | Traffic control | 235 [Initial value] none [Input mode] global configuration mode [Description] Adds a comment (remark) to the already-generated MAC access list. If this is executed with the "no" syntax, the comment is deleted from the MAC access list. [Note] You can use this command to add a comment even after the access list has been applied to LAN/SFP port and logical interface. (The last-written comment overwrites the previous one.) [Example] Create MAC access list #2000 which denies frames from MAC address 00-A0-DE-12-34-56, and add the comment "Test." SWR2310(config)#access-list 2001 deny mac 00A0.DE12.3456 0000.0000.0000 any SWR2310(config)#access-list 2001 description Test 9.1.9 Apply MAC access list [Syntax] access-group mac-acl-id direction no access-group mac-acl-id direction [Parameter] mac-acl-id : ID of MAC access list to apply direction : Specifies the direction of applicable frames Setting value in Description Apply to received frames [Initial value] none [Input mode] interface mode [Description] Applies a MAC access list to both LAN/SFP port and logical interface. If the received frame matches the conditions in the access list, the action in the access list will be the action (permit, deny) for the corresponding frame. If this is executed with the "no" syntax, the applied access list is deleted from both LAN/SFP port and logical interface. [Note] It is not possible to register multiple access lists for a single interface. The following restrictions apply. An LAN/SFP port for which an incoming frames access list is specified cannot be associated to an logical interface. An incoming frames access list cannot be applied to an LAN/SFP port that is associated with an logical interface. However, if an access list setting for incoming frames is specified for an LAN/SFP port that is associated with an logical interface in the startup config, then the setting for the lowest-numbered port is applied to the logical interface. [Example] Apply access list #2001 to received frames of LAN port #1. SWR2310(config)#interface port1.1 SWR2310(config-if)#access-group 2001 in

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278

[Initial value]
none
[Input mode]
global configuration mode
[Description]
Adds a comment (remark) to the already-generated MAC access list.
If this is executed with the "no" syntax, the comment is deleted from the MAC access list.
[Note]
You can use this command to add a comment even after the access list has been applied to LAN/SFP port and logical interface.
(The last-written comment overwrites the previous one.)
[Example]
Create MAC access list #2000 which denies frames from MAC address 00-A0-DE-12-34-56, and add the comment "Test."
SWR2310(config)#access-list 2001 deny mac 00A0.DE12.3456 0000.0000.0000 any
SWR2310(config)#access-list 2001 description Test
9.1.9 Apply MAC access list
[Syntax]
access-group
mac-acl-id
direction
no
access-group
mac-acl-id
direction
[Parameter]
mac-acl-id
:
<2001-3000>
ID of MAC access list to apply
direction
:
Specifies the direction of applicable frames
Setting value
Description
in
Apply to received frames
[Initial value]
none
[Input mode]
interface mode
[Description]
Applies a MAC access list to both LAN/SFP port and logical interface.
If the received frame matches the conditions in the access list, the action in the access list will be the action (permit, deny) for
the corresponding frame.
If this is executed with the "no" syntax, the applied access list is deleted from both LAN/SFP port and logical interface.
[Note]
It is not possible to register multiple access lists for a single interface.
The following restrictions apply.
An LAN/SFP port for which an incoming frames access list is specified cannot be associated to an logical interface.
An incoming frames access list cannot be applied to an LAN/SFP port that is associated with an logical interface. However, if
an access list setting for incoming frames is specified for an LAN/SFP port that is associated with an logical interface in the
startup config, then the setting for the lowest-numbered port is applied to the logical interface.
[Example]
Apply access list #2001 to received frames of LAN port #1.
SWR2310(config)#interface port1.1
SWR2310(config-if)#access-group 2001 in
Command Reference | Traffic control |
235