11.07.2015 Views

Catalyst 3750-E and 3560-E Switch Cisco IOS ... - DNIP . NET

Catalyst 3750-E and 3560-E Switch Cisco IOS ... - DNIP . NET

Catalyst 3750-E and 3560-E Switch Cisco IOS ... - DNIP . NET

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

permit (MAC access-list configuration)Chapter 2<strong>Catalyst</strong> <strong>3750</strong>-E <strong>and</strong> <strong>3560</strong>-E <strong>Switch</strong> <strong>Cisco</strong> <strong>IOS</strong> Comm<strong>and</strong>sUsage GuidelinesYou enter MAC access-list configuration mode by using the mac access-list extended globalconfiguration comm<strong>and</strong>.If you use the host keyword, you cannot enter an address mask; if you do not use the any or hostkeywords, you must enter an address mask.After an access control entry (ACE) is added to an access control list, an implied deny-any-anycondition exists at the end of the list. That is, if there are no matches, the packets are denied. However,before the first ACE is added, the list permits all packets.For more information about MAC-named extended access lists, see the software configuration guide forthis release.ExamplesThis example shows how to define the MAC-named extended access list to allow <strong>NET</strong>B<strong>IOS</strong> traffic fromany source to MAC address 00c0.00a0.03fa. Traffic matching this list is allowed.<strong>Switch</strong>(config-ext-macl)# permit any host 00c0.00a0.03fa netbiosThis example shows how to remove the permit condition from the MAC-named extended access list:<strong>Switch</strong>(config-ext-macl)# no permit any 00c0.00a0.03fa 0000.0000.0000 netbiosThis example permits all packets with Ethertype 0x4321:<strong>Switch</strong>(config-ext-macl)# permit any any 0x4321 0You can verify your settings by entering the show access-lists privileged EXEC comm<strong>and</strong>.Related Comm<strong>and</strong>s Comm<strong>and</strong> Descriptiondeny (MAC access-list Denies non-IP traffic to be forwarded if conditions are matched.configuration)mac access-list extended Creates an access list based on MAC addresses for non-IP traffic.show access-listsDisplays access control lists configured on a switch.2-426<strong>Catalyst</strong> <strong>3750</strong>-E <strong>and</strong> <strong>3560</strong>-E <strong>Switch</strong> Comm<strong>and</strong> ReferenceOL-9776-08

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!