Binding IP Source Guard ACLs to Ports

You can bind IPv4 ACLs meant for IP Source Guard (IPSG) ports (SG ACL) to a port or VLAN. IP Source Guard ACLs can then be configured to allow TCP traffic and all UDP traffic. The following task binds IPSG ACL sg-acl1 to port 1/1/2.
  1. Enter global configuration mode.
    device# configure terminal
  2. Configure an Ethernet Interface.
    device(config)# interface ethernet 1/1/2
  3. Enable IPSG on the port.
    device(config-if-e1000/1/1/2)# source-guard enable
  4. Bind the IPSG ACL to the port.
    device(config-if-e1000/1/1/2)# ip sg-access-group sg-acl1 in
    

The following example binds IPSG ACL sg-acl1 to port 1/1/2.

device# configure terminal
device(config)# interface ethernet 1/1/2
device(config-if-e1000/1/1/2)# source-guard enable
device(config-if-e1000/1/1/2)# ip sg-access-group sg-acl1 in

The following example unbinds the ACL.

device# configure terminal
device(config)# interface ethernet 1/1/2
device(config-if-e1000/1/1/2)# no ip sg-access-group sg-acl1 in
The following example binds an IPSG ACL for a VLAN interface.
device# configure terminal
device(config)# vlan 11
device(config-vlan-11)# source-guard enable
device(config-vlan-11)# ip sg-access-group sg-acl1 in

The following example defines IP Source Guard ACL sg123 to allow all TCP traffic and all UDP traffic.

device# configure terminal
device(config)# ip sg-access-list sg123
device(config-sg-sg123)# permit tcp any any
device(config-sg-sg123)# permit udp any any
device(config-sg-sg123)# exit
device(config)# 

The following example defines IP Source Guard ACL sg456 to allow TCP traffic destined for any port number from 100 through 200.

device# configure terminal
device(config)# ip sg-access-list sg456
device(config-sg-sg123)# permit tcp any range 100 200
device(config-sg-sg123)# exit
device(config)# 

The following example binds IP Source Guard ACL sg-acl1 to port 1/1/2.

device# configure terminal
device(config)# interface ethernet 1/1/2
device(config-if-e1000/1/1/2)# source-guard enable
device(config-if-e1000/1/1/2)# ip sg-access-group sg-acl1

The following example unbinds the ACL.

device# configure terminal
device(config)# interface ethernet 1/1/2
device(config-if-e1000/1/1/2)# no ip sg-access-group sg-acl1