Follow these steps to apply ACLs for traffic filtering.
device# configure terminal
device(config)# ip access-list extended acl1 2015/04/02-13:22:39, [SSMD-1400], 2506, SW/device | Active | DCE, INFO, device, IPv4 access list acl1 is created.
device(conf-ipacl-ext)# permit tcp any any sync 2015/04/02-13:25:28, [SSMD-1404], 2507, SW/device | Active | DCE, INFO, device, IPv4 access list acl1 rule sequence number 10 is added.
device(conf-ipacl-ext)# permit tcp any any rst 2015/04/02-13:26:48, [SSMD-1404], 2508, SW/device | Active | DCE, INFO, device, IPv4 access list acl1 rule sequence number 20 is added.
device(conf-ipacl-ext)# permit icmp any any 2015/04/02-13:28:20, [SSMD-1404], 2509, SW/device | Active | DCE, INFO, device, IPv4 access list acl1 rule sequence number 30 is added.
device(conf-ipacl-ext)# permit udp any any 2015/04/02-13:30:15, [SSMD-1404], 2510, SW/device | Active | DCE, INFO, device, IPv4 access list acl1 rule sequence number 40 is added.
device(conf-ipacl-ext)# exit
device(config)# do show running-config ip access-list extended acl1 ip access-list extended acl1 seq 10 permit tcp any any sync seq 20 permit tcp any any rst seq 30 permit icmp any any seq 40 permit udp any any !
device(config)# class-map aclFilter
device(config-classmap)# match access-group acl1
device(config-classmap)# exit
device(config)# do show running-config class-map aclFilter class-map aclFilter match access-group acl1 !
device(config)# policy-map policyAclFilter
device(config-policymap)# class aclFilter
device(config-policymap-class)# police cir 220000 cbs 50000 eir 36000 ebs 400000
device(config-policymap-class-police)# end
device# show policy-map detail policyAclFilter Policy-Map policyAclFilter Class aclFilter Police cir 220000 cbs 50000 eir 36000 ebs 400000 Bound To:None
device# configure terminal
device(config)# interface ethernet 1/2
device(conf-if-eth-1/2)# service-policy in policyAclFilter 2015/04/02-14:13:31, [SSMD-1405], 2511, SW/device | Active | DCE, INFO, device, IPv4 access list acl1 configured on interface Ethernet 1/2 at Ingress by FbQos_9_11.
device(conf-if-eth-1/2)# end
device# show policy-map detail policyAclFilter Policy-Map policyAclFilter Class aclFilter Police cir 220000 cbs 50000 eir 36000 ebs 400000 Bound To: Et 1/2(in)
device# copy running-config startup-config
device# configure terminal device(config)# ip access-list extended acl1 device(conf-ipacl-ext)# permit tcp any any sync device(conf-ipacl-ext)# permit tcp any any rst device(conf-ipacl-ext)# permit icmp any any device(conf-ipacl-ext)# permit udp any any device(config)# do show running-config ip access-list extended acl1 device(config)# class-map aclFilter device(config-classmap)# match access-group acl1 device(config-classmap)# exit device(config)# do show running-config class-map aclFilter device(config)# policy-map policyAclFilter device(config-policymap)# class aclFilter device(config-policymap-class)# police cir 220000 cbs 50000 eir 36000 ebs 400000 device(config-policymap-class-police)# end device# show policy-map detail policyAclFilter device# configure terminal device(config)# interface ethernet 1/2 device(conf-if-eth-1/2)# service-policy in policyAclFilter device(conf-if-eth-1/2)# end device# show policy-map detail policyAclFilter device# copy running-config startup-config