02.10.2013 Views

FTOS Configuration Guide for the C-Series - Force10 Networks

FTOS Configuration Guide for the C-Series - Force10 Networks

FTOS Configuration Guide for the C-Series - Force10 Networks

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

• Source MAC host address<br />

• Destination MAC host address<br />

• E<strong>the</strong>rnet frame type of <strong>the</strong> traffic<br />

Both standard and extended ACLs allow you to filter traffic with any MAC address. Your first decision in<br />

configuring MAC ACLs is to decide whe<strong>the</strong>r <strong>the</strong> ACL will filter based solely on <strong>the</strong> MAC source address<br />

or based on additional factors.<br />

The well-known MAC addresses (also known as protocol addresses) 0180c2000000 through<br />

0180c200000f are always permitted, even if you configure a MAC ACL deny filter <strong>for</strong> <strong>the</strong>se addresses.<br />

This default prevents SpanningTree loops when <strong>the</strong> mac learning-limit command is configured on<br />

Spanning Tree-enabled ports.<br />

Note: (For EF cards only) When ACL logging and byte counters are enabled simultaneously, <strong>the</strong> byte<br />

counter may show <strong>the</strong> wrong value. Instead, enable packet counter with logging.<br />

Note: MAC accounting accounts <strong>for</strong> packets denied by a MAC ACL when mirroring is configured.<br />

The following are additional facts about MAC addresses:<br />

• Each system is pre-assigned a block of MAC addresses that are stored in <strong>the</strong> backplane EEPROM.<br />

• E<strong>the</strong>rScale E-<strong>Series</strong> systems have 1K pre-allocated <strong>for</strong> MAC addresses.<br />

• TeraScale E1200 and E600 systems pre-allocate 2K <strong>for</strong> MAC addresses; <strong>the</strong> E300 pre-allocates 1.5K.<br />

• Port/VLAN MAC addresses do not change after a system reboot.<br />

• The MAC address on <strong>the</strong> management port of <strong>the</strong> RPM is not part of <strong>the</strong> system MAC address<br />

allocation pool.<br />

MAC ACLs are supported over VLAN interfaces on E-<strong>Series</strong> TeraScale systems.<br />

<strong>Configuration</strong> Task List <strong>for</strong> MAC ACLs<br />

The following list includes <strong>the</strong> configuration tasks <strong>for</strong> MAC ACLs and MAC Addressing:<br />

• Configuring a standard MAC ACL on page 191 (mandatory)<br />

• Configuring an extended MAC ACL on page 193 (mandatory)<br />

• Assigning a MAC ACL to an interface on page 196 (mandatory)<br />

• Specifying a CAM portion <strong>for</strong> MAC ACLs on page 197 (optional)<br />

For a complete listing of all commands related to MAC addresses and MAC ACLs, refer to<br />

Configuring a standard MAC ACL<br />

Standard MAC ACLs filter traffic based on <strong>the</strong> source MAC address. Since traffic passes through <strong>the</strong> ACL<br />

in <strong>the</strong> order of <strong>the</strong> filters’ sequence, you can configure <strong>the</strong> MAC ACL by first entering <strong>the</strong> MAC ACCESS<br />

LIST mode and <strong>the</strong>n assigning a sequence number to <strong>the</strong> filter.<br />

<strong>FTOS</strong> <strong>Configuration</strong> <strong>Guide</strong>, version 7.7.1.0 191

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!