02.10.2013 Views

FTOS Configuration Guide for the C-Series - Force10 Networks

FTOS Configuration Guide for the C-Series - Force10 Networks

FTOS Configuration Guide for the C-Series - Force10 Networks

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Step Command Syntax Command Mode Purpose<br />

2<br />

{deny | permit} {any |<br />

source-mac-address mask} [count [byte]]<br />

[log]<br />

Figure 99 illustrates a standard MAC ACL in which <strong>the</strong> sequence numbers were assigned by <strong>FTOS</strong>. The<br />

filters were assigned sequence numbers based on <strong>the</strong> order in which <strong>the</strong>y were configured (<strong>for</strong> example,<br />

<strong>the</strong> first filter was given <strong>the</strong> lowest sequence number). The show config command in <strong>the</strong> MAC ACCESS<br />

LIST mode displays <strong>the</strong> two filters with <strong>the</strong> sequence numbers 5 and 10.<br />

Figure 99 Standard MAC ACL Example<br />

To view a specific configured MAC ACLs, use <strong>the</strong> show mac accounting access-list access-list-name<br />

command (Figure 100) in <strong>the</strong> EXEC privilege mode.<br />

Figure 100 show mac accounting access-list Command Example<br />

To delete a filter, enter <strong>the</strong> show config in <strong>the</strong> MAC ACCESS LIST mode and locate <strong>the</strong> sequence<br />

number of <strong>the</strong> filter you want to delete; <strong>the</strong>n use <strong>the</strong> no seq sequence-number command in <strong>the</strong> MAC<br />

ACCESS LIST mode.<br />

Configuring an extended MAC ACL<br />

MAC ACCESS<br />

LIST<br />

<strong>Force10</strong>(conf)#mac access standard belmont<br />

<strong>Force10</strong>(config-std-macl)#permit 00:00:00:11:32:00<br />

<strong>Force10</strong>(config-std-macl)#permit any<br />

<strong>Force10</strong>(config-std-macl)#show config<br />

!<br />

mac access-list standard belmont<br />

seq 5 permit 00:00:00:11:32:00<br />

seq 10 permit any<br />

<strong>Force10</strong>(config-std-macl)#<br />

Configure a MAC ACL filter.<br />

The any keyword filters on any<br />

source MAC address. log is not<br />

supported on C-<strong>Series</strong>.<br />

<strong>Force10</strong>#show mac accounting access-list belmont interface gigabite<strong>the</strong>rnet 0/1 in<br />

Standard mac access-list belmont on GigabitE<strong>the</strong>rnet 0/1<br />

seq 5 permit 00:00:00:11:32:00<br />

seq 10 permit any<br />

<strong>Force10</strong>#<br />

Extended MAC ACLs filter on source and destination MAC addresses. In addition, you have <strong>the</strong> option of<br />

filtering traffic based on <strong>the</strong> E<strong>the</strong>rnet frame structure. <strong>FTOS</strong> offers <strong>the</strong> option to filter traffic based on one<br />

of three E<strong>the</strong>rnet frame <strong>for</strong>mats.<br />

<strong>FTOS</strong> <strong>Configuration</strong> <strong>Guide</strong>, version 7.7.1.0 193

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!