Cisco及华为网络技术论坛

基于MAC的访问控制列表详解


来源: 作者: 出处:Vlan9.com 2007-12-22 进入论坛
  • 关 键 词:

  Creating Named MAC Extended ACLs

  Step 1 配置终端进入全局配置模式

  Step 2 mac access-list extended name Define an extended MAC access list using a name.

  Step 3

  {deny | permit}

  {any | host source MACaddress | source MAC address mask}

  {any |host destination MAC address | destination MAC address mask} [type mask | lsap lsap mask | aarp | amber | dec-spanning | decnet-iv | diagnostic | dsm | etype-6000 | etype-8042 | lat | lavc-sca | mop-console | mop-dump | msdos | mumps | netbios | vines-echo |vines-ip | xns-idp | 0-65535]

  [cos cos]

  Step 4 end Return to privileged EXEC mode.

  Step 5 show access-lists [number | name] Show the access list configuration.

  Step 6 copy running-config startup-config (Optional) Save your entries in the configuration file.

  This example shows how to create and display an access list named mac1, denying only EtherType

  DECnet Phase IV traffic, but permitting all other types of traffic.

  Switch(config)# mac access-list extended mac1

  Switch(config-ext-macl)# deny any any decnet-iv

  Switch(config-ext-macl)# permit any any

  Switch(config-ext-macl)# end

  Switch # show access-lists

  Extended MAC access list mac1

  10 deny any any decnet-iv

  20 permit any any

更多请看Cisco与华为技术网(Vlan9.com)访问控制列表(ACL)介绍访问控制列表ACL基础介绍专题,或进入论坛讨论。

vlan9_logo
相关专题

论坛精华
阅读排行榜
最新技术文档
热门关键字导读