ip access-group
ip access-group
{
acl-name
}
{
in
|
out
}
[
logging enable
]no ip access-group
{acl-name
}
{
in
|
out
}
[
logging enable
]ACLs are not applied to interfaces by default.
Interface subtype configuration modes
multiple-interface configuration mode
In multiple interface configuration (MIF) mode, ACLs can be bound only to inbound traffic.
If you attempt to apply an egress ACL in multiple interface configuration mode, an error message is displayed.
In multiple interface configuration mode, you can configure a maximum range of eight interfaces with the same ACL simultaneously.
In multiple interface configuration mode, all interfaces are checked before the ACL is applied, and if an interface is not eligible for the ACL to be applied, binding fails on all designated intefaces, and an error message is displayed.
If an ACL is removed from multiple interfaces simultaneously but cannot be removed from one or more of the interfaces, the unbind operation nevertheless succeeds on the other designated interfaces.
Through a virtual routing interface, you have the following options:
To remove an ACL from an interface,
use one of the no
forms of this command.
The following example creates a named extended
IPv4 ACL, defines rules in the ACL, and applies it to inbound traffic on an
Ethernet interface. Because the ip access-group
command in this case includes the logging enable
option, when the deny statement in the ACL is
matched (note the log option in the statement),
it is logged.
device# configure terminal device(config)# ip access-list extended block_telnet device(config-ext-ipacl-block_telnet)# deny tcp host 10.157.22.26 any eq telnet log device(config-ext-ipacl-block_telnet)# permit ip any any device(config-ext-ipacl-block_telnet)# interface ethernet 1/1/1 device(config-if-e10000-1/1/1)# ip access-group block_telnet in logging enable
The following example binds several ACLs, including IPv6, IPv4, and MAC ACLs, to VLAN 555.
device# configure terminal device(config)# vlan 555 by port device(config-vlan-555)# lag 10 device(config-vlan-555)# interface ve 555 device(config-vlan-555)# ipv6 access-group scale25 in device(config-vlan-555)# ipv6 access-group scale15 out device(config-vlan-555)# mac access-group mac_acl1 in device(config-vlan-555)# ip access-group 123 in device(config-vlan-555)# ip access-group 134 out device(config-vlan-555)# exit device(config)#
The following example applies IPv6, IPv4, and MAC ACLs to LAG 10 and enables logging of traffic that matches any statement within the applied ACLs that contains the log keyword.
device# configure terminal device(config)# vlan 558 by port device(config-vlan-558)# lag 10 device(config-vlan-558)# ipv6 access-group scale12 in lag 10 logging enable device(config-vlan-558)# mac access-group mac_acl in lag 10 device(config-vlan-558)# ip access-group 134 in lag 10 logging enable
The following example applies IPv4, IPv6, and MAC ACLs to LAG 10 within the VLAN and enables logging of traffic that matches statements that contain the log keyword within the applied ACLs.
device# configure terminal device(config)# vlan 558 by port device(config-vlan-558)# lag 10 device(config-vlan-558)# ipv6 access-group scale12 in lag 10 logging enable device(config-vlan-558)# mac access-group mac_acl in lag 10 device(config-vlan-558)# ip access-group 134 in lag 10 logging enable
The following example applies an IPv4 ACL to multiple interfaces.
device# configure terminal device(config)# interface ethernet 1/1/15 to 1/1/20 device(config-mif-1/1/15-1/1/20)# ip access-group V4-ACL in Warning: Binding of large ACL Operation may take few minutes SYSLOG: <14> Sep 25 01:32:43 device ACL: V4-ACL applied to eth 1/1/15. SYSLOG: <14> Sep 25 01:32:43 device ACL: V4-ACL applied to eth 1/1/16. SYSLOG: <14> Sep 25 01:32:43 device ACL: V4-ACL applied to eth 1/1/17. SYSLOG: <14> Sep 25 01:32:43 device ACL: V4-ACL applied to eth 1/1/18. SYSLOG: <14> Sep 25 01:32:43 device ACL: V4-ACL applied to eth 1/1/19. SYSLOG: <14> Sep 25 01:32:43 device ACL: V4-ACL applied to eth 1/1/20. device(config-mif-1/1/15-1/1/20)# end device#
| Release version | Command history |
|---|---|
| 08.0.95 | This command was modified to include the logging enable option. |
| 10.0.20 | This command was modified to add the multiple interface configuration option. |