ip access-group

Applies IPv4 access control lists (ACLs) to traffic entering or exiting an interface.
Syntax
ip access-group { acl-name } { in | out } [ logging enable ]
no ip access-group {acl-name } { in | out } [ logging enable ]
Command Default

ACLs are not applied to interfaces.

Parameters
acl-name
Specifies a valid ACL name.
in
Applies the ACL to inbound traffic on the port.
out
Applies the ACL to outbound traffic on the port.
[ logging enable ]
Turns logging on for matched statements in the ACL that also include a log action.
Modes

Interface subtype configuration modes

Usage Guidelines

Through a virtual routing interface, you have the following options:

  • (Default) Apply an ACL to all ports of the VLAN.
  • One or both of the following options:
    • Apply an ACL to specified ports.
    • Apply an ACL to one or more ranges of ports.

To remove an ACL from an interface, use one of the no forms of this command.

Examples

The following example creates a named extended IPv4 ACL, defines rules in the ACL, and applies it to inbound traffic on an Ethernet interface. Because the ip access-group command in this case includes the logging enable option, when the deny statement in the ACL is matched (note the log option in the statement), it is logged.

device# configure terminal
device(config)# ip access-list extended block_telnet
device(config-ext-ipacl-block_telnet)# deny tcp host 10.157.22.26 any eq telnet log
device(config-ext-ipacl-block_telnet)# permit ip any any
device(config-ext-ipacl-block_telnet)# interface ethernet 1/1/1
device(config-if-e10000-1/1/1)# ip access-group block_telnet in logging enable

The following example binds several ACLs, including IPv6, IPv4, and MAC ACLs, to VLAN 555.

device# configure terminal
device(config)# vlan 555 by port
device(config-vlan-555)# lag 10
device(config-vlan-555)# interface ve 555
device(config-vlan-555)# ipv6 access-group scale25 in
device(config-vlan-555)# ipv6 access-group scale15 out
device(config-vlan-555)# mac access-group mac_acl1 in
device(config-vlan-555)# ip access-group 123 in
device(config-vlan-555)# ip access-group 134 out
device(config-vlan-555)# exit
device(config)# 

The following example applies IPv6, IPv4, and MAC ACLs to LAG 10 and enables logging of traffic that matches any statement within the applied ACLs that contains the log keyword.

device# configure terminal
device(config)# vlan 558 by port
device(config-vlan-558)# lag 10
device(config-vlan-558)# ipv6 access-group scale12 in lag 10 logging enable
device(config-vlan-558)# mac access-group mac_acl in lag 10
device(config-vlan-558)# ip access-group 134 in lag 10 logging enable

The following example applies IPv4, IPv6, and MAC ACLs to LAG 10 within the VLAN and enables logging of traffic that matches statements that contain the log keyword within the applied ACLs.

device# configure terminal
device(config)# vlan 558 by port
device(config-vlan-558)# lag 10
device(config-vlan-558)# ipv6 access-group scale12 in lag 10 logging enable
device(config-vlan-558)# mac access-group mac_acl in lag 10
device(config-vlan-558)# ip access-group 134 in lag 10 logging enable
History
Release version Command history
08.0.95 This command was modified to include the logging enable option.