I am attempting to perform simple ACL-based packet filtering on a Cisco ESS3300-based (ruggedized) switch that is running IOS-XE version 17.06.02 (network-advantage feature set). The switch allows me to configure SVIs, and performs inter-VLAN routing as expected (even though the "ip routing" command is rejected). However, the switch rejects the "ip access-group" command on SVIs, and that command is not listed in context-sensitive help while in interface configuration mode.
I don't see any mention of this limitation in the configuration guides or online discussions.
Am I missing something?