Static MAC
This example shows an ACL that will only allow the MAC address 01:1c:23:11:5a:e0 to pass traffic on this port and will furthermore ensure that all packets can only come from the 192.168.1.32 address. The /32 indicates the full 32 bits must match, and shorter masks can be used to, for example, lock a device to a specific subnet. This would typically be used on a Default Deny VLAN to allow a specific MAC/device access.
Static Mac Procedure
- Open a Panorama PON (EMS) session, click on the Profile icon button and the ACL tab.
- Select the EMS ACL Create a new profile icon and name the ACL profile to StaticMac-1.
- Click on the Create Rule button and perform the following steps:

Step 1: Enter "Filter 1" in Rule Name: entry box:
Step 2: Select "Basic ACL" from the ACL Type: Dropdown
Step 3: Select "Permit" from the Action: Dropdown
Step 4: Select "Static Mac(s)" from the SourceMAC(s): dropdown
Step 5: Add the MAC address "01:1c:23:11:5a:e0" to the Source Mac(s) Add entry box
Step 6: Add Bit count: "32" to the Source Mac(s) Add entry box
Step 7: Click on the Add button to add the MAC address and bit count to the Source Mac(s) window
Step 8: Select the MAC address entry in the Source Mac(s) window
Step 9: Enter "1" in the Max MAC(s) entry box
Step 10: Enter "1" in the Max IPs Per MAC entry box
Step 11: Enter the IP address "192.168.1.32" in the Bound SRC IP(s): entry box
Step 12: Add Bit count: "32" in the Bound SRC IP(s): entry box
Step 13: Click on the Add button to add the Bound SRC IP(s) and bit count to the Bound SRC IP(s): window
Step 14: Click on the Save button to save the rule profile
- Click on the Apply button to add the ACL profile to the Profile Name window list.
- After the Profile has been generated the ACL status is displayed. Click on the Close button to complete the ACL profile.
On this page