ip sg-access-group
ip sg-access-groupacl-namein[ethernetunit/slot/porttounit/slot/port|ethernetunit/slot/port][laglag-idtolag-id|laglag-id]no ip sg-access-groupacl-namein[ethernetunit/slot/porttounit/slot/port|ethernetunit/slot/port][laglag-idtolag-id|laglag-id]Interface configuration mode
VLAN configuration mode
The
source-guard enable command must be configured on the interface before an IPSG ACL can be bound to it.
An IPSG ACL cannot be bound to both an Ethernet interface and a VLAN on the same port simultaneously.
For Interface configuration mode, this command is supported only for Ethernet interfaces and VLAG interfaces.
The
no form of the command unbinds the ACL from the interface.
The following example binds IPSG ACL sg-acl1 to port 1/1/2.
device# configure terminal device(config)# interface ethernet 1/1/2 device(config-if-e1000/1/1/2)# source-guard enable device(config-if-e1000/1/1/2)# ip sg-access-group sg-acl1 in
The following example unbinds the ACL.
device# configure terminal device(config)# interface ethernet 1/1/2 device(config-if-e1000/1/1/2)# no ip sg-access-group sg-acl1 in
| Release version | Command history |
|---|---|
| 08.0.95 | This command was introduced. |