18.10.2013 Views

FTOS Command Reference for the S-Series - Force10 Networks

FTOS Command Reference for the S-Series - Force10 Networks

FTOS Command Reference for the S-Series - Force10 Networks

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Parameters<br />

To remove this filter, use one of <strong>the</strong> following:<br />

deny e<strong>the</strong>r-type<br />

• Use <strong>the</strong> no seq sequence-number command syntax if you know <strong>the</strong> filter’s sequence<br />

number or<br />

• Use <strong>the</strong> no deny e<strong>the</strong>r-type protocol-type-number {destination-mac-address<br />

mac-address-mask | any} vlan vlan-id {source-mac-address mac-address-mask |<br />

any} command.<br />

protocol-type-number Enter a number from 600 to FFFF as <strong>the</strong> specific E<strong>the</strong>rnet type<br />

traffic to drop.<br />

destination-mac-address<br />

mac-address-mask<br />

Defaults Not configured.<br />

<strong>Command</strong> Modes ACCESS-LIST (config-ext-nacl)<br />

Enter a MAC address and mask in <strong>the</strong> nn:nn:nn:nn:nn <strong>for</strong>mat.<br />

For <strong>the</strong> MAC address mask, specify which bits in <strong>the</strong> MAC address<br />

must match.<br />

The MAC ACL supports an inverse mask, <strong>the</strong>re<strong>for</strong>e, a mask of<br />

ff:ff:ff:ff:ff:ff allows entries that do not match and a mask of<br />

00:00:00:00:00:00 only allows entries that match exactly.<br />

any Enter <strong>the</strong> keyword any to match and drop specific E<strong>the</strong>rnet traffic<br />

on <strong>the</strong> interface.<br />

vlan vlan-id Enter <strong>the</strong> keyword vlan followed by <strong>the</strong> VLAN ID to filter traffic<br />

associated with a specific VLAN.<br />

Range: 1 to 4094<br />

To filter all VLAN traffic specify VLAN 1.<br />

source-mac-address<br />

mac-address-mask<br />

Enter a MAC address and mask in <strong>the</strong> nn:nn:nn:nn:nn <strong>for</strong>mat.<br />

For <strong>the</strong> MAC address mask, specify which bits in <strong>the</strong> MAC address<br />

must match.<br />

The MAC ACL supports an inverse mask, <strong>the</strong>re<strong>for</strong>e, a mask of<br />

ff:ff:ff:ff:ff:ff allows entries that do not match and a mask of<br />

00:00:00:00:00:00 only allows entries that match exactly.<br />

count (OPTIONAL) Enter <strong>the</strong> keyword count to count packets processed<br />

by <strong>the</strong> filter.<br />

byte (OPTIONAL) Enter <strong>the</strong> keyword byte to count bytes processed by<br />

<strong>the</strong> filter.<br />

log (OPTIONAL) Enter <strong>the</strong> keyword log to have <strong>the</strong> in<strong>for</strong>mation kept in<br />

an ACL log file.<br />

order (OPTIONAL) Enter <strong>the</strong> keyword order to specify <strong>the</strong> QoS order of<br />

priority <strong>for</strong> <strong>the</strong> ACL entry.<br />

Range: 0-254 (where 0 is <strong>the</strong> highest priority and 254 is <strong>the</strong><br />

lowest; lower order numbers have a higher priority)<br />

Default: If <strong>the</strong> order option is not configure, by default ACLs will<br />

have <strong>the</strong> lowest default order (255).<br />

monitor (OPTIONAL) Enter <strong>the</strong> keyword monitor to monitor traffic on <strong>the</strong><br />

monitoring interface specified in <strong>the</strong> flow-based monitoring session<br />

along with <strong>the</strong> filter operation.<br />

<strong>FTOS</strong> <strong>Command</strong> Line Interface <strong>Reference</strong>, version 7.6.1.0 319

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!