
ACCESS-LIST 12 - 35
12.2.2 deny
mac-access-list
Specifies packets to reject
Supported in the following platforms:
• RFS7000
• RFS6000
• RFS4000
• AP71xx
• AP650
• AP6511
• AP6532
Syntax
deny[<source-MAC>|any|host]
deny <source-MAC> <AA-BB-CC-DD-EE-FF> <dest-MAC> <AA-BB-CC-DD-EE-FF> [dot1p <0-
7>|log|rule-precedence <1-5000>[rule-description <WORD>|type [8021q|<1-
65535>|aarp|appletalk|arp|ip|ipv6|ipx|mint|rarp|wisp] [log|rule-precedence <1-5000>
rule-desription <WORD>]|vlan <1-4095> [log|rule-precedence|type[8021q|<1-
65535>|aarp|appletalk|arp|ip|
ipv6|ipx|mint|rarp|wisp]]
deny [any|host] <dest-MAC> <dest-mask> [dot1p <0-7>|log|rule-precedence <1-
5000>[rule-description <WORD>|type [8021q|<1-65535>|aarp|appletalk|
arp|ip|ipv6|ipx|mint|rarp|wisp] [log|rule-precedence]|vlan <1-4095> [log|rule-
precedence<1-5000> rule-desription <WORD>|type[8021q|<1-65535>|aarp|appletalk|
arp|ip|ipv6|ipx|mint|rarp|wisp]]
NOTE: Use a decimal value representation of ethertypes to implement a permit/deny
designation for a packet. The command set for MAC ACLs provide the hexadecimal
values for each listed ethertype. The controller supports all ethertypes. Use the decimal
equivalent of the ethertype listed for any other ethertype.
Kommentare zu diesen Handbüchern