Applying ACLs to VLANs
IPv4, IPv6, and MAC ACLs can be bound to the same VLAN.
In VLAN configuration sub-mode, you can apply an ACL to all ports in the VLAN, to LAG ports, or to selected ports or LAGs in the VLAN.
Perform the following steps to bind a previously created ACL to a VLAN.
- Enter global configuration mode
- Enter VLAN configuration sub-mode for the VLAN where the ACL is to be applied.
- Bind an ACL to the VLAN.
- Use the
ip access-groupcommand followed by the ACL name or ID and the direction to bind an IPv4 ACL to the VLAN.device(config-vlan-200)# ip access-group 99 in
- Use the
ipv6 access-groupcommand followed by the ACL name or ID and the direction to bind an IPv6 ACL to the VLAN.device(config-vlan-200)# ipv6 access-group v6 out
- Use the
mac access-groupcommand followed by the ACL name and the direction to bind a MAC ACL to the VLAN.device(config-vlan-200)# mac access-group macl1 in
- Use the
The following example binds several ACLs, including IPv6, IPv4, and MAC ACLs, to VLAN 555.
device# configure terminal device(config)# vlan 555 by port device(config-vlan-555)# lag 10 device(config-vlan-555)# router-interface ve 555 device(config-vlan-555)# ipv6 access-group scale25 in device(config-vlan-555)# ipv6 access-group scale15 out device(config-vlan-555)# mac access-group mac_acl1 in device(config-vlan-555)# ip access-group 123 in device(config-vlan-555)# ip access-group 134 out device(config-vlan-555)# exit device(config)#
The following example applies IPv4, IPv6, and MAC ACLs to LAG interface 10 within the VLAN and enables logging of traffic that matches statements that contain the log keyword within the applied ACLs.
device# configure terminal device(config)# vlan 558 by port device(config-vlan-558)# lag 10 device(config-vlan-558)# ipv6 access-group scale12 in lag 10 logging enable device(config-vlan-558)# mac access-group mac_acl in lag 10 device(config-vlan-558)# ip access-group 134 in lag 10 logging enable