Syntax
Call up the command with the following parameters:
ip access-group <access-list-number(1-20)> {in|out}
The parameters have the following meaning:
Parameter
Description
Range of values / note
access-list-
number
Number of the access control list
1 ... 20
in
Specifies that incoming packets are fil‐
tered
-
out
Specifies that outgoing packets are fil‐
tered
-
Note
Restrictions when filtering layer 2 interfaces
The filtering of outgoing packets is not supported on layer 2 interfaces.
Filtering on a layer 2 interface using an IP access control list is only effective for IP packets.
To filter packets with other data formats, use an expanded MAC access control list.
Result
The packets are filtered according to the access control list (ACL).
Further notes
You disable the setting with the
no ip access-group
command.
You display the configuration of the access control list with the
show access-lists
command.
11.5.3.2
no ip access-group
Description
With this command, you disable the access control of the packets of an interface.
Requirement
You are in the Interface configuration mode.
The command prompt is as follows:
cli(config-if-$$$)#
Security and authentication
11.5 IP access control list
SCALANCE W770/W730 acc. to IEEE 802.11n Command Line Interface
558
Configuration Manual, 09/2017, C79000-G8976-C324-08