I've gone through the command references for multiple versions of WB.16.x, and there's no mention of this not being supported.
Yet on my 2920Gs:
On a VLAN - can only do an ip access-group xyz vlan-in
On an interface - can only do an ip access-group xyz in
No out availabe. I've tried WB.16.03.0003, WB.16.03.0007, WB.16.10.0007. Funny enough, on WB.15.18.0006 out does appear for VLAN.
Switch01(vlan-5)# ip access-group test
vlan-in Apply the IPv4 ACL for bridged and routed inbound packets on this VLAN.
Is this really true? I can only do inbound ACL on a 2920?
#ACL