Configuration Considerations for Applying IP ACLs

  • The name in the Filter-Id attribute is case-sensitive.
  • Dynamically assigned IP ACLs are subject to the same configuration restrictions as non-dynamically assigned IP ACLs.
  • Filters are supported for inbound traffic only. Outbound filters are not supported.
  • A maximum of one IP ACL per client can be configured in the inbound direction on an interface.
  • Static ACLs are not supported with a Web Authentication-enabled port.
  • Concurrent operation of a dynamic IP ACL and a static IP ACL is not supported.
  • Dynamic IP ACL assignment with Web Authentication is not supported in conjunction with any of the following features:
    • IP Source Guard
    • Rate limiting
    • Protection against ICMP or TCP Denial of Service (DoS) attacks
    • Policy-based routing
    • DHCP snooping
    • ARP inspection
    • Flexible authentication dynamic IPv4 ACLs and MAC ACLs
    • Static MAC ACLs
    • Static IPv4 access list
    • ACL logging