Solved

MAC Filtering

Posted on 2013-12-20
8
283 Views
Last Modified: 2013-12-23
Hi Experts,

I hope you can help me with this. Im trying to set up MAC filtering on a powerconnect 5448
However when i apply my ACL to the port it blocks all traffic even from the device, who's mac should be allowed

As a result im guessing i've configured something wrong so hopefully someone can spot the mistake

Here is my understanding of the fields

Priority - Self explanatory
Action - Self explanatory
Source MAC - MAC of machine or device in question
MAC Wild Card Mask - 00:00:00:00:00:00 for a explicit mac address
VLAN - vlan of port and device
Ethertype - should be 0x0800 for all traffic?

The only one im uncertain on is the ethertype
0
Comment
Question by:FSIFM
  • 3
  • 3
  • 2
8 Comments
 
LVL 45

Expert Comment

by:Craig Beck
ID: 39732315
Try Ethertype 0x0806 instead.  You're filtering by MAC, not IPv4.
0
 
LVL 11

Expert Comment

by:Miftaul
ID: 39732351
Ethernet II frame's "Type" field tells the OS what kind of data the frame carries

0x0800 means that the contents of the frame is an IPv4 packet
0
 
LVL 4

Author Comment

by:FSIFM
ID: 39735567
Hi Guys,

I tried 0x0806 and 0x0800. Still no luck? Any other ideas what could be causing the issue?
0
 
LVL 11

Expert Comment

by:Miftaul
ID: 39735611
Can you please run and give us the output,

console# show mac access-lists
console# show mac access-lists YOUR-ACL-NAME

Here is the example configuration:

console(config)#mac access-list extended ALLOW
console(config-mac-access-list)#Permit 3C97.0E86.9F42 0000.0000.0000 any
console(config-mac-access-list)#Deny any any

Then we apply on that specific interface
console(config)#mac access-group ALLOW in
0
Control application downtime with dependency maps

Visualize the interdependencies between application components better with Applications Manager's automated application discovery and dependency mapping feature. Resolve performance issues faster by quickly isolating problematic components.

 
LVL 4

Author Comment

by:FSIFM
ID: 39735622
SWI..DP108# show access-lists
MAC access list SJones
    permit  host b8:ca:3a:73:d6:24 any vlan 1 ethtype 0806
SWI..DP108# show access-lists
MAC access list SJones
    permit  host b8:ca:3a:73:d6:24 any vlan 1 ethtype 0806

SWI..DP108# show access-lists SJones
MAC access list SJones
    permit  host b8:ca:3a:73:d6:24 any vlan 1 ethtype 0806
0
 
LVL 45

Accepted Solution

by:
Craig Beck earned 250 total points
ID: 39735832
This is for a 6024, but might work on the 5448...

mac access-list ALLOW_PCS
 permit aa:bb:cc:dd:ee:ff 00:00:00:00:00:00 any vlan 1
 permit 00:11:22:33:44:55 00:00:00:00:00:00 any vlan 1
!
interface e1
 service-acl input ALLOW_PCS
interface e2
 service-acl input ALLOW_PCS

Open in new window

Replace the MAC addresses with real ones, and change the VLAN to whichever destination VLAN you want to allow that MAC to access.
0
 
LVL 11

Assisted Solution

by:Miftaul
Miftaul earned 250 total points
ID: 39735842
EtherType 0806 seems to be for Address Resolution Protocol (ARP)

Can you please remote "ethtype 0806" from the ACE.

Also please apply the ACL inbound to the interface.
0
 
LVL 4

Author Closing Comment

by:FSIFM
ID: 39736017
That did it! :) Turns out no ethertype needed to be provided

Cheers lads and Merry Xmas to you both
0

Featured Post

Microsoft Certification Exam 74-409

Veeam® is happy to provide the Microsoft community with a study guide prepared by MVP and MCT, Orin Thomas. This guide will take you through each of the exam objectives, helping you to prepare for and pass the examination.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article will step through configuring a SonicWALL appliance to utilize an internal DHCP server for Global VPN Client (GVC) hosts.  There are times when using an external (external to the SonicWALL) DHCP server, such as Windows Servers, isn’t pr…
I eventually solved a perplexing problem setting up telnet for a new switch.  I installed a new Cisco WS-03560X-24P switch connected to an existing Cisco 4506 running a WS-X4013-10GE Sup II-Plus. After configuring vlans and trunking,  I could no…
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, just open a new email message. In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…

911 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

20 Experts available now in Live!

Get 1:1 Help Now