Binding IP Source Guard ACLs to Ports
You can bind IPv4 ACLs meant for IP
Source Guard (IPSG) ports (SG ACL) to a port or VLAN. IP Source Guard ACLs can then
be
configured to allow TCP traffic and all UDP traffic. The following task binds IPSG
ACL
sg-acl1 to port 1/1/2.
- Enter global configuration mode.
- Configure an Ethernet Interface.
- Enable IPSG on the port.
- Bind the IPSG ACL to the port.
The following example binds IPSG ACL sg-acl1 to port 1/1/2.
device# configure terminal device(config)# interface ethernet 1/1/2 device(config-if-e1000/1/1/2)# source-guard enable device(config-if-e1000/1/1/2)# ip sg-access-group sg-acl1 in
The following example unbinds the ACL.
device# configure terminal device(config)# interface ethernet 1/1/2 device(config-if-e1000/1/1/2)# no ip sg-access-group sg-acl1 in
The following example binds an IPSG ACL for
a VLAN interface.
device# configure terminal device(config)# vlan 11 device(config-vlan-11)# source-guard enable device(config-vlan-11)# ip sg-access-group sg-acl1 in
The following example defines IP Source Guard ACL sg123 to allow all TCP traffic and all UDP traffic.
device# configure terminal device(config)# ip sg-access-list sg123 device(config-sg-sg123)# permit tcp any any device(config-sg-sg123)# permit udp any any device(config-sg-sg123)# exit device(config)#
The following example defines IP Source Guard ACL sg456 to allow TCP traffic destined for any port number from 100 through 200.
device# configure terminal device(config)# ip sg-access-list sg456 device(config-sg-sg123)# permit tcp any range 100 200 device(config-sg-sg123)# exit device(config)#
The following example binds IP Source Guard ACL sg-acl1 to port 1/1/2.
device# configure terminal device(config)# interface ethernet 1/1/2 device(config-if-e1000/1/1/2)# source-guard enable device(config-if-e1000/1/1/2)# ip sg-access-group sg-acl1