Restrictions for Creating an IP Access List and Applying It to an Interface
The following restrictions apply when configuring IPv4 and IPv6 access control lists (ACLs)
-
Application control engine (ACE)-specific counters are not supported.
-
Layer 3 IPv4 and IPv6 ACLs are not supported on the same interface.
-
MAC ACLs are not supported on Ethernet flow points (EFPs) or trunk EFP interfaces to which Layer 3 IPv4 or IPv6 ACLs are applied.
-
IPv4 and IPv6 ACLs are not currently supported on EFP interfaces. IPv4 and IPv6 ACLs are supported on physical interfaces, bridge-domain interfaces, and port-channel interfaces.
-
Layer 4 port-range functionality expands into Ternary Content-Addressable Memory (TCAM). IPv4 ACL scale is limited to 1K TCAM, Layer 2 ACL scale is limited to 1K TCAM entries.
-
Object-groups ACLs (IPv4 and IPv6 ACLs) are supported on Cisco ISR platforms.
-
The command any options is not supoprted.
-
Starting with Cisco IOS XE Cupertino Release 17.7.1, ACLs are supported on management interface, Gigabit 0.
-
An incoming access list filters all traffic entering a device, including both transit traffic and traffic destined for the device itself.
-
By default, an outgoing access list filters only transit traffic leaving a device, not traffic generated by the device. To have an outgoing access list also filter traffic originating from the device, use the global configuration commands ip access-list match-local-traffic and ipv6 access-list match-local-traffic, as appropriate. For more information, refer to the Creating an IP Access List and Applying It to an Interface and IPv6 Access Control Lists.

Feedback