Applying ACLs on Multiple Interfaces Simultaneously
Consider the following points when applying ACLs to multiple interfaces simultaneously.
- Only inbound ACLs can be applied to multiple interfaces simultaneously. An error message is displayed if you try to apply an outbound ACL.
- In multiple-interface configuration mode, you can configure a maximum range of eight interfaces with the same ACL simultaneously.
- You can also configure the
ip access-group frag denycommand on multiple IPv4 interfaces simultaneously. - If you are applying an IPv6 ACL, IPv6 must already be enabled on all specified interfaces.
- Validation is performed for all specified interfaces before the ACL is applied. If any interface fails validation, the ACL is not applied to any of the specified interfaces. An error message is displayed to report the failure.
- You can also remove an ACL from multiple interfaces at the same time. If the ACL has not been applied to one or more of the interfaces in the range, the operation still succeeds for interfaces on which the ACL has been applied.
Complete the following steps to apply an inbound ACL to multiple interfaces simultaneously.
- Enter
configure terminalto access global configuration mode. - Specify a range of interfaces to
be configured. Then apply an existing IPv4 or IPv6 ACL. On the same command
line, specify the direction as in. If
desired, include the logging enable option to
log matched statements that contain the keyword log.
device(config)# interface ethernet 1/1/2 to 1/1/4 device(config-mif-1/1/2-1/1/4)# ip access-group MY-ACL in device(config-mif-1/1/2-1/1/4)# exit device(config)#
The following example configures the ICX device to drop all packet fragments received on the interfaces being configured. The example then applies an existing IPv4 ACL to six interfaces simultaneously.
ICX8200-48 Router# configure terminal ICX8200-48 Router(config)# interface ethernet 1/1/15 to 1/1/20 ICX8200-48 Router(config-mif-1/1/15-1/1/20)# ip access-group frag deny ICX8200-48 Router(config-mif-1/1/15-1/1/20)# ip access-group V4-ACL in Warning: Binding of large ACL Operation may take few minutes ICX8200-48 Router(config-mif-1/1/15-1/1/20)# SYSLOG: <14> Sep 25 01:32:43 ICX8200-48 Router ACL: V4-ACL applied to eth 1/1/15. SYSLOG: <14> Sep 25 01:32:43 ICX8200-48 Router ACL: V4-ACL applied to eth 1/1/16. SYSLOG: <14> Sep 25 01:32:43 ICX8200-48 Router ACL: V4-ACL applied to eth 1/1/17. SYSLOG: <14> Sep 25 01:32:43 ICX8200-48 Router ACL: V4-ACL applied to eth 1/1/18. SYSLOG: <14> Sep 25 01:32:43 ICX8200-48 Router ACL: V4-ACL applied to eth 1/1/19. SYSLOG: <14> Sep 25 01:32:43 ICX8200-48 Router ACL: V4-ACL applied to eth 1/1/20. ICX8200-48 Router(config-mif-1/1/15-1/1/20)# end ICX8200-48 Router#
The following example applies an existing IPv6 ACL to the same set of interfaces and
verifies the configuration with the show running-config
command.
ICX8200-48 Router# configure terminal ICX8200-48 Router(config)# interface ethernet 1/1/15 to 1/1/20 ICX8200-48 Router(config-mif-1/1/15-1/1/20)# ipv6 access-group V6-ACL in Warning: Binding of large ACL Operation may take few minutes ICX8200-48 Router(config-mif-1/1/15-1/1/20)# SYSLOG: <14> Sep 25 01:33:32 ICX8200-48 Router ACL: V6-ACL applied to eth 1/1/15. SYSLOG: <14> Sep 25 01:33:32 ICX8200-48 Router ACL: V6-ACL applied to eth 1/1/16. SYSLOG: <14> Sep 25 01:33:32 ICX8200-48 Router ACL: V6-ACL applied to eth 1/1/17. SYSLOG: <14> Sep 25 01:33:32 ICX8200-48 Router ACL: V6-ACL applied to eth 1/1/18. SYSLOG: <14> Sep 25 01:33:32 ICX8200-48 Router ACL: V6-ACL applied to eth 1/1/19. SYSLOG: <14> Sep 25 01:33:32 ICX8200-48 Router ACL: V6-ACL applied to eth 1/1/20. ICX8200-48 Router(config-mif-1/1/15-1/1/20)# show running-config internet ethernet 1/1/15 to 1/1/20 interface ethernet 1/1/15 ip access-group V4-ACL in ip access-group frag deny ipv6 access-group V6-ACL in ! interface ethernet 1/1/16 ip access-group V4-ACL in ip access-group frag deny ipv6 access-group V6-ACL in ! interface ethernet 1/1/17 ip access-group V4-ACL in ip access-group frag deny ipv6 access-group V6-ACL in ! interface ethernet 1/1/18 ip access-group V4-ACL in ip access-group frag deny ipv6 access-group V6-ACL in ! interface ethernet 1/1/19 ip access-group V4-ACL in ip access-group frag deny ipv6 access-group V6-ACL in ! interface ethernet 1/1/20 ip access-group V4-ACL in ip access-group frag deny ipv6 access-group V6-ACL in !