扫一扫
关注微信公众号

基于MAC的访问控制列表详解
2009-01-11   

 

Creating Named MAC Extended ACLs

Step 1 配置终端进入全局配置模式

Step 2 mac access-list extended name Define an extended MAC access list using a name.

Step 3

{deny | permit}

{any | host source MACaddress | source MAC address mask}

{any |host destination MAC address | destination MAC address mask} [type mask | lsap lsap mask | aarp | amber | dec-spanning | decnet-iv | diagnostic | dsm | etype-6000 | etype-8042 | lat | lavc-sca | mop-console | mop-dump | msdos | mumps | netbios | vines-echo |vines-ip | xns-idp | 0-65535]

[cos cos]

Step 4 end Return to privileged EXEC mode.

Step 5 show access-lists [number | name] Show the access list configuration.

Step 6 copy running-config startup-config (Optional) Save your entries in the configuration file.

This example shows how to create and display an access list named mac1, denying only EtherType

DECnet Phase IV traffic, but permitting all other types of traffic.

Switch(config)# mac access-list extended mac1

Switch(config-ext-macl)# deny any any decnet-iv

Switch(config-ext-macl)# permit any any

Switch(config-ext-macl)# end

Switch # show access-lists

Extended MAC access list mac1

10 deny any any decnet-iv

20 permit any any

 

 


热词搜索:

上一篇:高端交换机的弹性分组环技术实现
下一篇:动态ACL配置详解(1)

分享到: 收藏