Use this procedure to apply an IPv4 ACL to filter ingress routed traffic on a VE interface (attached to a VLAN).
device# configure terminal
device(config)# interface ve 50
For IPv4 ACLs, specify the ingress direction and set the routed parameter.
device(config-if-ve-50)# ip access-group test_02 in routed