MAC ACLs are Layer 2 ACLs. A MAC ACL rule specifies whether the contents of a packet permit or deny access to the network. Depending on the options that are supported on a switch, you can configure rules to inspect the following fields of a packet:
- Source MAC address and source MAC mask
- Destination MAC address and destination MAC mask
- VLAN ID (or range of IDs)
- Class of Service (CoS, 802.1p)
- EtherType key (multiple preconfigured options, or user defined option)
You can do the following with MAC ACLs:
- Assign incoming packets to queues.
- Mirror or redirect incoming packets.
- Assign a data rate limit and bust size to incoming packets.
- Log the ACL actions.
- Apply a single MAC ACL to one or more interfaces.
- Apply multiple ACLs to a single interface; The ACL sequence number determines the order of execution, and the first rule takes precedence.
- However, you cannot configure a MAC ACL and an IP ACL on the same interface.
After you attach an ACL rule to an interface, all traffic that is not specifically permitted by the ACL is denied access.
For more information, see the following support articles:
- What are access control lists (ACLs) and how do they work with my NETGEAR Smart Switch or fully managed switch?
- What are IP access control lists (ACLs) and how do they work with my NETGEAR Smart Switch or fully managed switch?
- How do I configure access control lists (ACLs) on my NETGEAR Smart Switch or fully managed switch?