Binding IP Source Guard ACLs to Ports

You can bind IPv4 ACLs meant for IP Source Guard (IPSG) ports (SG ACL) to a port or VLAN. IP Source Guard ACLs can then be configured to allow TCP traffic and all UDP traffic. The following task binds IPSG ACL sg-acl1 to port 1/1/2.
  1. Enter global configuration mode.
    device# configure terminal
  2. Configure an Ethernet Interface.
    device(config)# interface ethernet 1/1/2
  3. Enable IPSG on the port.
    device(config-if-e1000/1/1/2)# source-guard enable
  4. Bind the IPSG ACL to the specified port, applying the ACL to inbound traffic.
    device(config-if-e1000/1/1/2)# ip sg-access-group sg-acl1 in
    

The following example defines IP Source Guard ACL sg-acl1.

device# configure terminal
device(config)# ip sg-access-list sg-acl1

The following example binds IPSG ACL sg-acl1 to port 1/1/2.

device# configure terminal
device(config)# interface ethernet 1/1/2
device(config-if-e1000/1/1/2)# source-guard enable
device(config-if-e1000/1/1/2)# ip sg-access-group sg-acl1

The following example unbinds the IPSG ACL.

device# configure terminal
device(config)# interface ethernet 1/1/2
device(config-if-e1000/1/1/2)# no ip sg-access-group sg-acl1
The following example creates and binds IPSG ACL sg-acl1 to port 1/1/2, applying the ACL to inbound traffic.
device# configure terminal
device(config)# interface ethernet 1/1/2
device(config-if-e1000/1/1/2)# source-guard enable
device(config-if-e1000/1/1/2)# ip sg-access-group sg-acl1 in
The following example unbinds the IPSG ACL from port 1/1/2.
device# configure terminal
device(config)# interface ethernet 1/1/2
device(config-if-e1000/1/1/2)# no ip sg-access-group sg-acl1 in
The following example creates and binds an IPSG ACL to a specified VLAN, applying the ACL to inbound traffic.
device# configure terminal
device(config)# vlan 11
device(config-vlan-11)# source-guard enable
device(config-vlan-11)# ip sg-access-group sg-acl1 in

The following example defines IPSG ACL sg123 to allow all TCP traffic and all UDP traffic.

device# configure terminal
device(config)# ip sg-access-list sg123
device(config-sg-sg123)# permit tcp any any
device(config-sg-sg123)# permit udp any any
device(config-sg-sg123)# exit
device(config)# 

The following example defines IPSG ACL sg456 to allow TCP traffic destined for any port number from 100 through 200.

device# configure terminal
device(config)# ip sg-access-list sg456
device(config-sg-sg123)# permit tcp any range 100 200
device(config-sg-sg123)# exit
device(config)#