ip sg-access-group

Binds an ingress IPv4 access control list (ACL) meant for IP Source Guard (IPSG) ports (SG ACL) to a port or VLAN.
Syntax
ip sg-access-groupacl-namein[ethernetunit/slot/porttounit/slot/port|ethernetunit/slot/port][laglag-idtolag-id|laglag-id]
no ip sg-access-groupacl-namein[ethernetunit/slot/porttounit/slot/port|ethernetunit/slot/port][laglag-idtolag-id|laglag-id]
Parameters
acl-name
Specifies the IPSG ACL to be bound to the interface.
in
Applies the ACL to inbound traffic.
ethernetunit/slot/port
Specifies the Ethernet interface and the interface ID in the unit/slot/port format.
tounit/slot/port
Specifies a range of Ethernet interfaces.
laglag-id
Specifies the LAG virtual interface.
tolag-id
Specifies a range of LAG IDs.
Modes

Interface configuration mode

VLAN configuration mode

Usage Guidelines

The source-guard enable command must be configured on the interface before an IPSG ACL can be bound to it.

An IPSG ACL cannot be bound to both an Ethernet interface and a VLAN on the same port simultaneously.

For Interface configuration mode, this command is supported only for Ethernet interfaces and VLAG interfaces.

The no form of the command unbinds the ACL from the interface.

Examples

The following example binds IPSG ACL sg-acl1 to port 1/1/2.

device# configure terminal
device(config)# interface ethernet 1/1/2
device(config-if-e1000/1/1/2)# source-guard enable
device(config-if-e1000/1/1/2)# ip sg-access-group sg-acl1 in

The following example unbinds the ACL.

device# configure terminal
device(config)# interface ethernet 1/1/2
device(config-if-e1000/1/1/2)# no ip sg-access-group sg-acl1 in

The following example binds an IPSG ACL for a VLAN interface.

device# configure terminal
device(config)# vlan 11
device(config-vlan-11)# source-guard enable
device(config-vlan-11)# ip sg-access-group sg-acl1 in


            
History
Release version Command history
08.0.95 This command was introduced.