Applying ACLs to VLANs

You can apply IPv4, IPv6, and MAC ACLs to VLANs.

IPv4, IPv6, and MAC ACLs can be bound to the same VLAN.

In VLAN configuration sub-mode, you can apply an ACL to all ports in the VLAN, to LAG ports, or to selected ports or LAGs in the VLAN.

Perform the following steps to bind a previously created ACL to a VLAN.

  1. Enter global configuration mode
    device# configure terminal
    device(config)#
    
  2. Enter VLAN configuration sub-mode for the VLAN where the ACL is to be applied.
    device(config)# vlan 200
    device(config-vlan-200)# 
  3. Bind an ACL to the VLAN.
    • Use the ip access-group command followed by the ACL name or ID and the direction to bind an IPv4 ACL to the VLAN.
      device(config-vlan-200)# ip access-group 99 in
    • Use the ipv6 access-group command followed by the ACL name or ID and the direction to bind an IPv6 ACL to the VLAN.
      device(config-vlan-200)# ipv6 access-group v6 out
    • Use the mac access-group command followed by the ACL name and the direction to bind a MAC ACL to the VLAN.
      device(config-vlan-200)# mac access-group macl1 in

The following example binds several ACLs, including IPv6, IPv4, and MAC ACLs, to VLAN 555.

device# configure terminal
device(config)# vlan 555 by port
device(config-vlan-555)# lag 10
device(config-vlan-555)# interface ve 555
device(config-vlan-555)# ipv6 access-group scale25 in
device(config-vlan-555)# ipv6 access-group scale15 out
device(config-vlan-555)# mac access-group mac_acl1 in
device(config-vlan-555)# ip access-group 123 in
device(config-vlan-555)# ip access-group 134 out
device(config-vlan-555)# exit
device(config)# 

The following example applies IPv4, IPv6, and MAC ACLs to LAG interface 10 within the VLAN and enables logging of traffic that matches statements that contain the log keyword within the applied ACLs.

device# configure terminal
device(config)# vlan 558 by port
device(config-vlan-558)# lag 10
device(config-vlan-558)# ipv6 access-group scale12 in lag 10 logging enable
device(config-vlan-558)# mac access-group mac_acl in lag 10
device(config-vlan-558)# ip access-group 134 in lag 10 logging enable