command to control access to an interface. To remove
the specified access group, use the
no form of
the command. Use the
access-list-name argument to specify a particular
IPv4 access list. Use the
keyword to filter on inbound packets or the egress keyword to filter on
outbound packets. Use the
argument to enable hardware counters for the access
are counted only when hardware counters are enabled using the hardware-count
argument. Denied packets are counted whether hardware counters are enabled or
To enter the dynamic template configuration
dynamic-template command in the
only for BNG).
dynamic template configuration mode, only the
keywords are displayed.
filtering applications using the ipv4/ipv6 access-group command, packet
counters are maintained in hardware for each direction. If an access group is
used on multiple interfaces in the same direction, then packets are counted for
each interface that has the hardware-count argument enabled.
If the access list
permits the addresses, the software continues to process the packet. If the
access list denies the address, the software discards the packet and returns an
Internet Control Message Protocol (ICMP) host unreachable message.
If the specified
access list does not exist, all packets are passed.
By default, the
unique or per-interface ACL statistics are disabled.