
12 - 38 WiNG CLI Reference Guide
Usage Guidelines
The deny command disallows traffic based on layer 2 (data-link layer) data. The MAC access list denies traffic from a
particular source MAC address or any MAC address. It can also disallow traffic from a list of MAC addresses based on the
source mask.
The MAC access list can disallow traffic based on the VLAN and ethertype.
•arp
•wisp
•ip
• 802.1q
host <dest-MAC> <AA-BB-CC-DD-
EE-FF> [dot1p <0-7>|log|rule-
precedence <1-5000>[rule-
description <WORD>|type
[8021q|<1-
65535>|aarp|appletalk|arp|ip|ipv6|i
px|mint|rarp|wisp] [log|rule-
precedence]|vlan <1-4095>
[log|rule-
precedence|type[8021q|<1-
65535>|aarp|appletalk|arp|ip|ipv6|i
px|mint|rarp|wisp]
host – Specify an exact source MAC address to match
• <dest-MAC> – Specify the destination MAC address
• dot1p <0-7> – Sets the 802.1p priority value from 0-7
• log – Generates log messages when the packet
coming from the interface matches an ACL entry. Log
messages are generated only for router ACLs.
• rule-precedence<1-5000>rule-description <WORD>
– Defines an integer value between 1-5000. This val-
ue sets the rule precedence in the ACL
• <1-5000> – Specify a precedence value from
1-5000
• rule-description – Access-list entry description
• <WORD> – Enter the description not exceeding
128 characters
• type[8021q|<1-65535>|aarp|apple-
talk|arp|ip|ipv6|ipx|mint|rarp|wisp] [log <0-7>|
rule-precedence <1-5000>] – Specify the EtherType
• 8021q – VLAN Ether Type (0x8100)
• <1-65535> – Ethernet Protocol number
• aarp – AARP Ether Type (0x80F3)
• appletalk – APPLETALK Ether Type (0x809B)
• arp – ARP Ether Type (0x0806)
• ip – IP Ether Type (0x0800)
• ipv6 – IPv6 Ether Type (0x86DD)
• ipx – IPX Ether Type (0x8137)
• mint – MINT Ether Type (0x8783)
• rarp – RARP Ether Type (0x8035)
• wisp –WISP Ether Type (0x8783)
• vlan <1-4095> [log|rule-precedence <1-5000>
rule-desription <WORD>|type – VLAN ID
• <1-4095> – Specify a VLAN ID from 1-4095
NOTE: MAC ACLs always takes precedence over IP based ACLs.
Kommentare zu diesen Handbüchern