Binding IP Source Guard ACLs to Ports
You can bind IPv4 ACLs meant for IP
Source Guard (IPSG) ports (SG ACL) to a port or VLAN. IP Source Guard ACLs can then
be
configured to allow TCP traffic and all UDP traffic. The following task binds IPSG
ACL
sg-acl1 to port 1/1/2.
- Enter global configuration mode.
- Configure an Ethernet Interface.
- Enable IPSG on the port.
- Bind the IPSG ACL to the specified port, applying the ACL to inbound traffic.
The following example defines IP Source Guard ACL sg-acl1.
device# configure terminal device(config)# ip sg-access-list sg-acl1
The following example binds IPSG ACL sg-acl1 to port 1/1/2.
device# configure terminal device(config)# interface ethernet 1/1/2 device(config-if-e1000/1/1/2)# source-guard enable device(config-if-e1000/1/1/2)# ip sg-access-group sg-acl1
The following example unbinds the IPSG ACL.
device# configure terminal device(config)# interface ethernet 1/1/2 device(config-if-e1000/1/1/2)# no ip sg-access-group sg-acl1
The following example creates and binds IPSG ACL sg-acl1 to port 1/1/2, applying
the ACL to inbound traffic.
device# configure terminal device(config)# interface ethernet 1/1/2 device(config-if-e1000/1/1/2)# source-guard enable device(config-if-e1000/1/1/2)# ip sg-access-group sg-acl1 in
The following example unbinds the IPSG ACL from port 1/1/2.
device# configure terminal device(config)# interface ethernet 1/1/2 device(config-if-e1000/1/1/2)# no ip sg-access-group sg-acl1 in
The following example creates and binds an
IPSG ACL to a specified VLAN, applying the ACL to inbound
traffic.
device# configure terminal device(config)# vlan 11 device(config-vlan-11)# source-guard enable device(config-vlan-11)# ip sg-access-group sg-acl1 in
The following example defines IPSG ACL sg123 to allow all TCP traffic and all UDP traffic.
device# configure terminal device(config)# ip sg-access-list sg123 device(config-sg-sg123)# permit tcp any any device(config-sg-sg123)# permit udp any any device(config-sg-sg123)# exit device(config)#