Deny (Extended Acls) - Dell 8 Command Reference Manual

Dell converged enhanced ethernet command reference
Hide thumbs Also See for 8:
Table of Contents

Advertisement

10

deny (extended ACLs)

deny (extended ACLs)
Configures a MAC address rule to drop traffic based on the source and destination MAC addresses.
Synopsis
deny {any | host MAC _ACL| MAC_ACL} {any | host MAC _ACL| MAC _ACL} [EtherType |arp |fcoe |
ipv4] [count]
no deny {any | host MAC _ACL| MAC_ACL} {any | host MAC _ACL| MAC _ACL} [EtherType |arp
|fcoe| ipv4]
Operands
any
host MAC_ACL
MAC_ACL
any
host MAC_ACL
MAC_ACL
Ethertype
arp
fcoe
ipv4
count
Defaults
By default, no MAC ACLs are configured.
Command
Feature Access Control List Configuration mode
Modes
Description
Use this command to configure rules to match and drop traffic based on the source and
destination MAC addresses and the protocol type. You can also enable counters for a specific rule.
There are 255 ACL counters supported per port group. Use the no deny command to remove a rule
from the MAC ACL.
Usage
The first set of {any | host MAC_ACL | MAC_ACL} parameters is specific to the source MAC
Guidelines
address. The second set of {any | host MAC_ACL | MAC_ACL} parameters is specific to the
destination MAC address.
Example
To create a rule in a MAC extended ACL to drop IPv4 traffic from the source MAC address
0022.3333.4444
of packets:
To delete a rule from a MAC extended ACL:
142
Specifies any source MAC address.
Specifies the source host MAC address for which to set deny conditions. Use
the format HHHH.HHHH.HHHH.
Specifies the source host MAC address for which to set deny conditions. Use
the format HHHH.HHHH.HHHH.
Specifies any destination MAC address.
Specifies the destination host address for which to set deny conditions. Use
the format HHHH.HHHH.HHHH.
Specifies the destination host address for which to set deny conditions. Use
the format HHHH.HHHH.HHHH.
Specifies the protocol number for which to set the deny conditions. The
range of valid values is 1536-65535.
Specifies to deny the Address Resolution Protocol (0x0806).
Specifies to deny the Fibre Channel over Ethernet Protocol (0x8906).
Specifies to deny the IPv4 protocol (0x0800).
Enables counting of the packets matching the rule.
to the destination MAC address
switch(conf-macl-ext)#deny 0022.3333.4444 0022.3333.5555 ipv4 count
and to enable the counting
0022.3333.5555
Dell Converged Enhanced Ethernet Command Reference
53-1002115-01

Advertisement

Table of Contents
loading

Table of Contents