ip access-group
ip access-group
{
acl-name
}
{
in
|
out
}
[
logging enable
]no ip access-group
{acl-name
}
{
in
|
out
}
[
logging enable
]ACLs are not applied to interfaces.
Interface subtype configuration modes
Through a virtual routing interface, you have the following options:
To remove an ACL from an interface, use one of the
no forms of this command.
The following example creates a named extended
IPv4 ACL, defines rules in the ACL, and applies it to inbound traffic on an
Ethernet interface. Because the ip access-group
command in this case includes the logging enable
option, when the deny statement in the ACL is
matched (note the log option in the statement),
it is logged.
device# configure terminal device(config)# ip access-list extended block_telnet device(config-ext-ipacl-block_telnet)# deny tcp host 10.157.22.26 any eq telnet log device(config-ext-ipacl-block_telnet)# permit ip any any device(config-ext-ipacl-block_telnet)# interface ethernet 1/1/1 device(config-if-e10000-1/1/1)# ip access-group block_telnet in logging enable
The following example binds several ACLs, including IPv6, IPv4, and MAC ACLs, to VLAN 555.
device# configure terminal device(config)# vlan 555 by port device(config-vlan-555)# lag 10 device(config-vlan-555)# interface ve 555 device(config-vlan-555)# ipv6 access-group scale25 in device(config-vlan-555)# ipv6 access-group scale15 out device(config-vlan-555)# mac access-group mac_acl1 in device(config-vlan-555)# ip access-group 123 in device(config-vlan-555)# ip access-group 134 out device(config-vlan-555)# exit device(config)#
The following example applies IPv6, IPv4, and MAC ACLs to LAG 10 and enables logging of traffic that matches any statement within the applied ACLs that contains the log keyword.
device# configure terminal device(config)# vlan 558 by port device(config-vlan-558)# lag 10 device(config-vlan-558)# ipv6 access-group scale12 in lag 10 logging enable device(config-vlan-558)# mac access-group mac_acl in lag 10 device(config-vlan-558)# ip access-group 134 in lag 10 logging enable
The following example applies IPv4, IPv6, and MAC ACLs to LAG 10 within the VLAN and enables logging of traffic that matches statements that contain the log keyword within the applied ACLs.
device# configure terminal device(config)# vlan 558 by port device(config-vlan-558)# lag 10 device(config-vlan-558)# ipv6 access-group scale12 in lag 10 logging enable device(config-vlan-558)# mac access-group mac_acl in lag 10 device(config-vlan-558)# ip access-group 134 in lag 10 logging enable
| Release version | Command history |
|---|---|
| 08.0.95 | This command was modified to include the logging enable option. |