beautypg.com

Deny – Brocade Mobility RFS Controller CLI Reference Guide (Supporting software release 5.5.0.0 and later) User Manual

Page 929

background image

Brocade Mobility RFS Controller CLI Reference Guide

917

53-1003098-01

12

deny

mac-access-list

Creates a deny rule that marks packets (from a specified source MAC and/or to a specified
destination MAC) for rejection. You can also use this command to modify an existing deny rule.

NOTE

Use a decimal value representation to implement a

permit/deny

designation for a packet. The

command set for MAC ACLs provide the hexadecimal values for each listed EtherType. Use the
decimal equivalent of the EtherType listed for any other EtherType.

Supported in the following platforms:

Access Points — Brocade Mobility 650 Access Point, Brocade Mobility 6511 Access Point,
Brocade Mobility 1220 Access Point, Brocade Mobility 71XX Access Point, Brocade
Mobility 1240 Access Point

Wireless Controllers — Brocade Mobility RFS4000, Brocade Mobility RFS6000, Brocade
Mobility RFS7000

Service Platforms — Brocade Mobility RFS9510

Syntax:

deny [ |any|host ]

[ |any|host ]

(dot1p <0-7>,type

[8021q|<1-65535>|aarp|appletalk|arp|ip|ipv6|ipx|mint|rarp|wisp],

vlan <1-4095>,log,rule-precedence <1-5000>) {(rule-description

)}

Parameters

deny [ |any|host ]

[ |any|host ]

(dot1p <0-7>,type

[8021q|<1-65535>|aarp|appletalk|arp|ip|ipv6|ipx|mint|rarp|wisp],

vlan <1-4095>,log,rule-precedence <1-5000>) {(rule-description )}

show

Displays running system information

page 429

write

Writes information to memory or terminal

page 425

Command

Description

Reference


Configures the source MAC address and mask to match

– Specify the source MAC address to match.

– Specify the source MAC address mask.

Packets received from the specified MAC addresses are dropped.

any

Identifies all devices as the source to deny access. Packets received from any source are dropped.

host

Identifies a specific host as the source to deny access

– Specify the source host’s exact MAC address to match. Packets received from
the specified host are dropped.