Configuring MAC ACLs
2. Enter one of the following commands:
3. mac port access-group access-list
4. (Optional) show running-config aclmgr
5. (Optional) copy running-config startup-config
DETAILED STEPS
Command or Action
Step 1
configure terminal
Example:
switch# configure terminal
switch(config)#
Step 2
Enter one of the following commands:
• interface ethernet slot/port
• interface port-channel channel-number
Example:
switch(config)# interface ethernet 2/1
switch(config-if)#
Example:
switch(config)# interface port-channel 5
switch(config-if)#
Step 3
mac port access-group access-list
Example:
switch(config-if)# mac port access-group acl-01
Step 4
(Optional) show running-config aclmgr
Example:
switch(config-if)# show running-config aclmgr
Step 5
(Optional) copy running-config startup-config
Example:
switch(config-if)# copy running-config
startup-config
Applying a MAC ACL as a VACL
You can apply a MAC ACL as a VACL.
Enabling or Disabling MAC Packet Classification
You can enable or disable MAC packet classification on a Layer 2 interface.
• interface ethernet slot/port
• interface port-channel channel-number
Cisco Nexus 9000 Series NX-OS Security Configuration Guide, Release 9.x
Purpose
Enters global configuration mode.
• Enters interface configuration mode for a Layer 2 or
Layer 3 interface.
• Enters interface configuration mode for a Layer 2 or
Layer 3 port-channel interface.
Applies a MAC ACL to the interface.
Displays the ACL configuration.
Copies the running configuration to the startup
configuration.
Applying a MAC ACL as a VACL
291