02.10.2013 Views

FTOS Configuration Guide for the C-Series - Force10 Networks

FTOS Configuration Guide for the C-Series - Force10 Networks

FTOS Configuration Guide for the C-Series - Force10 Networks

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Step Command Syntax Command Mode Purpose<br />

2<br />

seq sequence-number {deny | permit} {any |<br />

host mac-address | mac-source-address<br />

mac-source-address-mask} {any | host<br />

mac-address | mac-destination-address<br />

mac-destination-address-mask}<br />

[e<strong>the</strong>rtype-operator] [count [byte]] [log]<br />

MAC ACCESS<br />

LIST<br />

When you create <strong>the</strong> filters with specific sequence numbers, you can create <strong>the</strong> filters in any order and<br />

<strong>FTOS</strong> orders <strong>the</strong> filters correctly.<br />

Figure 101 illustrates how <strong>the</strong> seq command orders <strong>the</strong> filters according to <strong>the</strong> sequence number assigned.<br />

In <strong>the</strong> example, filter 15 was configured be<strong>for</strong>e filter 5, but <strong>the</strong> show config command displays <strong>the</strong> filters<br />

in <strong>the</strong> correct order.<br />

Figure 101 Extended MAC ACL Using <strong>the</strong> seq Command Example<br />

Configure a MAC ACL filter.<br />

The any keyword filters on<br />

any source MAC address.<br />

The host keyword followed<br />

by a MAC address filters all<br />

MAC addresses with that<br />

host.<br />

The optional<br />

e<strong>the</strong>rtype-operator values<br />

are discussed in Table 13.<br />

log not supported on<br />

E<strong>the</strong>rScale line cards or<br />

C-<strong>Series</strong>.<br />

Note: Keep in mind that when assigning sequence numbers to filters you might need to insert a new filter.<br />

To prevent reconfiguring multiple filters, assign sequence numbers in multiples of five or ano<strong>the</strong>r number.<br />

<strong>Force10</strong>(conf)#mac access-list extended dunedin<br />

<strong>Force10</strong>(config-ext-macl)#seq 15 deny 00:00:00:11:ed:00 ff:ff:ff:ff:ff:ff 00:00:00:ab:11:00<br />

ff:ff:ff:ff:ff:ff<br />

<strong>Force10</strong>(config-ext-macl)#seq 5 permit host 00:00:00:00:45:ef any<br />

<strong>Force10</strong>(config-ext-macl)#show config<br />

!<br />

mac access-list extended dunedin<br />

seq 5 permit host 00:00:00:00:45:ef any<br />

seq 15 deny 00:00:00:00:ec:00 ff:ff:ff:ff:ff:ff 00:00:00:aa:00:00 ff:ff:ff:ff:ff:ff<br />

<strong>Force10</strong>(config-ext-macl)#<br />

If you are creating a standard ACL with only one or two filters, you can let <strong>FTOS</strong> assign a sequence<br />

number based on <strong>the</strong> order in which <strong>the</strong> filters are configured. <strong>FTOS</strong> assigns filters in multiples of 5.<br />

To configure a filter without a specified sequence number, use <strong>the</strong>se commands in <strong>the</strong> following sequence,<br />

starting in <strong>the</strong> CONFIGURATION mode:<br />

Step Command Syntax Command Mode Purpose<br />

1 mac access-list extended<br />

access-list-name<br />

CONFIGURATION Create an extended MAC ACL and<br />

assign it a unique name.<br />

<strong>FTOS</strong> <strong>Configuration</strong> <strong>Guide</strong>, version 7.7.1.0 195

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!