User's Manual
A
CCESS
 C
ONTROL
 L
IST
 C
OMMANDS
4-127
Command Mode
Privileged Exec
Example 
Related Commands
mask (IP ACL) (3-122)
ip access-group 
This command binds a port to an IP ACL. Use the no form to remove the 
port.
Syntax
[no] ip access-group acl_name {in | out}
• acl_name – Name of the ACL. (Maximum length: 16 characters)
• in – Indicates that this list applies to ingress packets.
• out – Indicates that this list applies to egress packets.
Default Setting
None
Command Mode
Interface Configuration (Ethernet)
Command Usage
• A port can only be bound to one ACL.
• If a port is already bound to an ACL and you bind it to a different ACL, 
the switch will replace the old binding with the new one. 
• You must configure a mask for an ACL rule before you can bind it to 
a port.
Console#show access-list ip mask-precedence
IP ingress mask ACL:
 mask host any
 mask 255.255.255.0 any
Console#










