Solved

MAC Filtering

Posted on 2013-12-20
8
289 Views
Last Modified: 2013-12-23
Hi Experts,

I hope you can help me with this. Im trying to set up MAC filtering on a powerconnect 5448
However when i apply my ACL to the port it blocks all traffic even from the device, who's mac should be allowed

As a result im guessing i've configured something wrong so hopefully someone can spot the mistake

Here is my understanding of the fields

Priority - Self explanatory
Action - Self explanatory
Source MAC - MAC of machine or device in question
MAC Wild Card Mask - 00:00:00:00:00:00 for a explicit mac address
VLAN - vlan of port and device
Ethertype - should be 0x0800 for all traffic?

The only one im uncertain on is the ethertype
0
Comment
Question by:FSIFM
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 3
  • 2
8 Comments
 
LVL 46

Expert Comment

by:Craig Beck
ID: 39732315
Try Ethertype 0x0806 instead.  You're filtering by MAC, not IPv4.
0
 
LVL 11

Expert Comment

by:Miftaul
ID: 39732351
Ethernet II frame's "Type" field tells the OS what kind of data the frame carries

0x0800 means that the contents of the frame is an IPv4 packet
0
 
LVL 4

Author Comment

by:FSIFM
ID: 39735567
Hi Guys,

I tried 0x0806 and 0x0800. Still no luck? Any other ideas what could be causing the issue?
0
Simple, centralized multimedia control

Watch and learn to see how ATEN provided an easy and effective way for three jointly-owned pubs to control the 60 televisions located across their three venues utilizing the ATEN Control System, Modular Matrix Switch and HDBaseT extenders.

 
LVL 11

Expert Comment

by:Miftaul
ID: 39735611
Can you please run and give us the output,

console# show mac access-lists
console# show mac access-lists YOUR-ACL-NAME

Here is the example configuration:

console(config)#mac access-list extended ALLOW
console(config-mac-access-list)#Permit 3C97.0E86.9F42 0000.0000.0000 any
console(config-mac-access-list)#Deny any any

Then we apply on that specific interface
console(config)#mac access-group ALLOW in
0
 
LVL 4

Author Comment

by:FSIFM
ID: 39735622
SWI..DP108# show access-lists
MAC access list SJones
    permit  host b8:ca:3a:73:d6:24 any vlan 1 ethtype 0806
SWI..DP108# show access-lists
MAC access list SJones
    permit  host b8:ca:3a:73:d6:24 any vlan 1 ethtype 0806

SWI..DP108# show access-lists SJones
MAC access list SJones
    permit  host b8:ca:3a:73:d6:24 any vlan 1 ethtype 0806
0
 
LVL 46

Accepted Solution

by:
Craig Beck earned 250 total points
ID: 39735832
This is for a 6024, but might work on the 5448...

mac access-list ALLOW_PCS
 permit aa:bb:cc:dd:ee:ff 00:00:00:00:00:00 any vlan 1
 permit 00:11:22:33:44:55 00:00:00:00:00:00 any vlan 1
!
interface e1
 service-acl input ALLOW_PCS
interface e2
 service-acl input ALLOW_PCS

Open in new window

Replace the MAC addresses with real ones, and change the VLAN to whichever destination VLAN you want to allow that MAC to access.
0
 
LVL 11

Assisted Solution

by:Miftaul
Miftaul earned 250 total points
ID: 39735842
EtherType 0806 seems to be for Address Resolution Protocol (ARP)

Can you please remote "ethtype 0806" from the ACE.

Also please apply the ACL inbound to the interface.
0
 
LVL 4

Author Closing Comment

by:FSIFM
ID: 39736017
That did it! :) Turns out no ethertype needed to be provided

Cheers lads and Merry Xmas to you both
0

Featured Post

Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
access vs trunk with voice vlan 2 69
Connect two buildings 6 57
VTP servers with 3650 switches 5 46
NAS ISCSI Sharing 8 40
The following recovery method will work on All Cisco Switchs that run ISO software. You will need a good copy of the IOS version you want you use saved on your PC and a Com's Cable. The software for these switches comes as a .tar file. Tar is …
In this tutorial I will show you with short command examples how to obtain a packet footprint of all traffic flowing thru your Juniper device running ScreenOS. I do not know the exact firmware requirement, but I think the fprofile command is availab…
Although Jacob Bernoulli (1654-1705) has been credited as the creator of "Binomial Distribution Table", Gottfried Leibniz (1646-1716) did his dissertation on the subject in 1666; Leibniz you may recall is the co-inventor of "Calculus" and beat Isaac…
In a recent question (https://www.experts-exchange.com/questions/29004105/Run-AutoHotkey-script-directly-from-Notepad.html) here at Experts Exchange, a member asked how to run an AutoHotkey script (.AHK) directly from Notepad++ (aka NPP). This video…

749 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question