Getting started with Ethernet rules

Ethernet rules are lists of matching criteria and actions that define whether Ethernet protocol traffic is allowed or discarded.

Ethernet rules are used by layer 2 physical interfaces on Engines.

The traffic matching in Ethernet rules is based on the Source and Destination MAC Address in the packets. Any Ethernet network traffic, such as ARP, RARP, IPv6, Cisco Discovery Protocol (CDP), and Spanning Tree Protocol (STP), can be checked against the Ethernet rules. Ethernet traffic can be allowed or discarded. Regardless of the action taken, a matching rule can also create a log or alert entry.

The following types of interfaces can stop traffic when the Discard action is used:

  • Inline Layer 2 Engine Interfaces on Engines

For the following types of interfaces, only the Allow action is available:

  • Capture Interfaces on Engines

You can use the first Insert Point in the template to make exceptions to this behavior for certain MAC addresses or Logical Interfaces. We recommend that you insert any other changes at the second insert point.

Make sure that your Ethernet rules direct IP traffic for inspection against Access rules by applying the default IPv4 and IPv6 Services to traffic. When traffic does not match any Ethernet rule, the traffic is let through without further inspection.