I hate to revisit this mention from a few years back, but can you apply ACLs to a single port when running the router image on an ICX6450?if you would like to actually block anything on physical port 20 from getting out to the internet, that's also possible, but it requires creating and applying the ACL a little differently
For some reason, I’m only seeing the ‘ip access-group’ option when configuring a ``ve`` not a physical interface (and because I’m looking to add 802.1p marking to packets flowing across a single, unrouted VLAN, that doesn’t seem to work).