Solved

MAC Filtering

Posted on 2013-12-20
8
288 Views
Last Modified: 2013-12-23
Hi Experts,

I hope you can help me with this. Im trying to set up MAC filtering on a powerconnect 5448
However when i apply my ACL to the port it blocks all traffic even from the device, who's mac should be allowed

As a result im guessing i've configured something wrong so hopefully someone can spot the mistake

Here is my understanding of the fields

Priority - Self explanatory
Action - Self explanatory
Source MAC - MAC of machine or device in question
MAC Wild Card Mask - 00:00:00:00:00:00 for a explicit mac address
VLAN - vlan of port and device
Ethertype - should be 0x0800 for all traffic?

The only one im uncertain on is the ethertype
0
Comment
Question by:FSIFM
  • 3
  • 3
  • 2
8 Comments
 
LVL 45

Expert Comment

by:Craig Beck
ID: 39732315
Try Ethertype 0x0806 instead.  You're filtering by MAC, not IPv4.
0
 
LVL 11

Expert Comment

by:Miftaul
ID: 39732351
Ethernet II frame's "Type" field tells the OS what kind of data the frame carries

0x0800 means that the contents of the frame is an IPv4 packet
0
 
LVL 4

Author Comment

by:FSIFM
ID: 39735567
Hi Guys,

I tried 0x0806 and 0x0800. Still no luck? Any other ideas what could be causing the issue?
0
Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

 
LVL 11

Expert Comment

by:Miftaul
ID: 39735611
Can you please run and give us the output,

console# show mac access-lists
console# show mac access-lists YOUR-ACL-NAME

Here is the example configuration:

console(config)#mac access-list extended ALLOW
console(config-mac-access-list)#Permit 3C97.0E86.9F42 0000.0000.0000 any
console(config-mac-access-list)#Deny any any

Then we apply on that specific interface
console(config)#mac access-group ALLOW in
0
 
LVL 4

Author Comment

by:FSIFM
ID: 39735622
SWI..DP108# show access-lists
MAC access list SJones
    permit  host b8:ca:3a:73:d6:24 any vlan 1 ethtype 0806
SWI..DP108# show access-lists
MAC access list SJones
    permit  host b8:ca:3a:73:d6:24 any vlan 1 ethtype 0806

SWI..DP108# show access-lists SJones
MAC access list SJones
    permit  host b8:ca:3a:73:d6:24 any vlan 1 ethtype 0806
0
 
LVL 45

Accepted Solution

by:
Craig Beck earned 250 total points
ID: 39735832
This is for a 6024, but might work on the 5448...

mac access-list ALLOW_PCS
 permit aa:bb:cc:dd:ee:ff 00:00:00:00:00:00 any vlan 1
 permit 00:11:22:33:44:55 00:00:00:00:00:00 any vlan 1
!
interface e1
 service-acl input ALLOW_PCS
interface e2
 service-acl input ALLOW_PCS

Open in new window

Replace the MAC addresses with real ones, and change the VLAN to whichever destination VLAN you want to allow that MAC to access.
0
 
LVL 11

Assisted Solution

by:Miftaul
Miftaul earned 250 total points
ID: 39735842
EtherType 0806 seems to be for Address Resolution Protocol (ARP)

Can you please remote "ethtype 0806" from the ACE.

Also please apply the ACL inbound to the interface.
0
 
LVL 4

Author Closing Comment

by:FSIFM
ID: 39736017
That did it! :) Turns out no ethertype needed to be provided

Cheers lads and Merry Xmas to you both
0

Featured Post

Free Tool: IP Lookup

Get more info about an IP address or domain name, such as organization, abuse contacts and geolocation.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Cant browse or ping a particular URL 2 44
P2P and MPLS 3 60
ssh setup on Cisco swith 11 86
Receiving wifi on an underground station 22 96
Do you have a computer or other electronic gear that is attached to a rat nest of cables, or alternatively have your cables all bundled nice at neat?  If so then read this post to sidstep common pitfalls. When I was a student at DeVry University,…
I eventually solved a perplexing problem setting up telnet for a new switch.  I installed a new Cisco WS-03560X-24P switch connected to an existing Cisco 4506 running a WS-X4013-10GE Sup II-Plus. After configuring vlans and trunking,  I could no…
This video shows how to use Hyena, from SystemTools Software, to bulk import 100 user accounts from an external text file. View in 1080p for best video quality.

828 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question