How is access control configured on an AR

You can configure a traffic policy on an AR to implement access control. For example, to prevent users on a network segment from accessing the Internet, perform the following operations:
acl number 2015 //Configure an ACL to define the network segment.
rule 5 permit source
traffic classifier c1 operator or //Configure a traffic classifier and reference the ACL.
if-match acl 2015
traffic behavior b1 //Configure a traffic behavior and define the deny action.
traffic policy p1 //Configure a traffic policy and bind the traffic classifier and traffic behavior to the traffic policy.
classifier c1 behavior b1
interface Ethernet5/0/0
traffic-policy p1 inbound //Apply the traffic policy to an interface.

