Applying ACLs on Multiple Interfaces Simultaneously

Consider the following points when applying ACLs to multiple interfaces simultaneously.

  • Only inbound ACLs can be applied to multiple interfaces simultaneously. An error message is displayed if you try to apply an outbound ACL.
  • In multiple-interface configuration mode, you can configure a maximum range of eight interfaces with the same ACL simultaneously.
  • You can also configure the ip access-group frag deny command on multiple IPv4 interfaces simultaneously.
  • If you are applying an IPv6 ACL, IPv6 must already be enabled on all specified interfaces.
  • Validation is performed for all specified interfaces before the ACL is applied. If any interface fails validation, the ACL is not applied to any of the specified interfaces. An error message is displayed to report the failure.
  • You can also remove an ACL from multiple interfaces at the same time. If the ACL has not been applied to one or more of the interfaces in the range, the operation still succeeds for interfaces on which the ACL has been applied.

Complete the following steps to apply an inbound ACL to multiple interfaces simultaneously.

  1. Enter configure terminal to access global configuration mode.
    device# configure terminal
    
  2. Specify a range of interfaces to be configured. Then apply an existing IPv4 or IPv6 ACL. On the same command line, specify the direction as in. If desired, include the logging enable option to log matched statements that contain the keyword log.
    • For an IPv4 ACL, use the ip access-group command.
    device(config)# interface ethernet 1/1/2 to 1/1/4
    device(config-mif-1/1/2-1/1/4)# ip access-group MY-ACL in
    device(config-mif-1/1/2-1/1/4)# exit
    device(config)#
    • For an IPv6 ACL, use the ipv6 access-group command.
    device(config)# interface ethernet 1/2/5 to 1/2/8 
    device(config-mif-1/2/5-1/2/8)# ipv6 access-group MYV6-ACL in logging enable
    device(config-mif-1/2/5-1/2/8)# end
    device#

The following example configures the ICX device to drop all packet fragments received on the interfaces being configured. The example then applies an existing IPv4 ACL to six interfaces simultaneously.

ICX8200-48 Router# configure terminal
ICX8200-48 Router(config)# interface ethernet 1/1/15 to 1/1/20
ICX8200-48 Router(config-mif-1/1/15-1/1/20)# ip access-group frag deny
ICX8200-48 Router(config-mif-1/1/15-1/1/20)# ip access-group V4-ACL in
Warning: Binding of large ACL Operation may take few minutes 
ICX8200-48 Router(config-mif-1/1/15-1/1/20)#
SYSLOG: <14> Sep 25 01:32:43 ICX8200-48 Router ACL: V4-ACL applied to eth 1/1/15.  

SYSLOG: <14> Sep 25 01:32:43 ICX8200-48 Router ACL: V4-ACL applied to eth 1/1/16.  

SYSLOG: <14> Sep 25 01:32:43 ICX8200-48 Router ACL: V4-ACL applied to eth 1/1/17.  

SYSLOG: <14> Sep 25 01:32:43 ICX8200-48 Router ACL: V4-ACL applied to eth 1/1/18.  

SYSLOG: <14> Sep 25 01:32:43 ICX8200-48 Router ACL: V4-ACL applied to eth 1/1/19.  

SYSLOG: <14> Sep 25 01:32:43 ICX8200-48 Router ACL: V4-ACL applied to eth 1/1/20. 

ICX8200-48 Router(config-mif-1/1/15-1/1/20)# end

ICX8200-48 Router#

The following example applies an existing IPv6 ACL to the same set of interfaces and verifies the configuration with the show running-config command.

ICX8200-48 Router# configure terminal
ICX8200-48 Router(config)# interface ethernet 1/1/15 to 1/1/20
ICX8200-48 Router(config-mif-1/1/15-1/1/20)# ipv6 access-group V6-ACL in
Warning: Binding of large ACL Operation may take few minutes 
ICX8200-48 Router(config-mif-1/1/15-1/1/20)#
SYSLOG: <14> Sep 25 01:33:32 ICX8200-48 Router ACL: V6-ACL applied to eth 1/1/15.  

SYSLOG: <14> Sep 25 01:33:32 ICX8200-48 Router ACL: V6-ACL applied to eth 1/1/16.  

SYSLOG: <14> Sep 25 01:33:32 ICX8200-48 Router ACL: V6-ACL applied to eth 1/1/17.  

SYSLOG: <14> Sep 25 01:33:32 ICX8200-48 Router ACL: V6-ACL applied to eth 1/1/18.  

SYSLOG: <14> Sep 25 01:33:32 ICX8200-48 Router ACL: V6-ACL applied to eth 1/1/19.  

SYSLOG: <14> Sep 25 01:33:32 ICX8200-48 Router ACL: V6-ACL applied to eth 1/1/20.  

ICX8200-48 Router(config-mif-1/1/15-1/1/20)# show running-config internet ethernet 1/1/15 to 1/1/20
interface ethernet 1/1/15
 ip access-group V4-ACL in
 ip access-group frag deny
 ipv6 access-group V6-ACL in
!
interface ethernet 1/1/16
 ip access-group V4-ACL in
 ip access-group frag deny
 ipv6 access-group V6-ACL in
!
interface ethernet 1/1/17
 ip access-group V4-ACL in
 ip access-group frag deny
 ipv6 access-group V6-ACL in
!
interface ethernet 1/1/18
 ip access-group V4-ACL in
 ip access-group frag deny
 ipv6 access-group V6-ACL in
!
interface ethernet 1/1/19
 ip access-group V4-ACL in
 ip access-group frag deny
 ipv6 access-group V6-ACL in
!
interface ethernet 1/1/20                                         
 ip access-group V4-ACL in
 ip access-group frag deny
 ipv6 access-group V6-ACL in
!