3750 Port based ACL logging

3750 Port based ACL logging

NewsGroups | Search | Tools
 comp.dcom.sys.cisco  Post an article  get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content  add this group's latest topics to your Google content  YahooMyWeb Yahoo!  Google Google  Windows Live Favorites Windows Live  del.icio.us del.icio.us  digg digg  Add to Netscape Netscape
Subject Author Date
3750 Port based ACL logging Kent 05-15-2008
Posted by Kent on May 15, 2008, 2:00 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Hi all,
With the below test config I can't seem to generate a single log entry
from the ACL. Has anyone had experience in logging with port based
ACL's on the 3750? With the below config the icmp traffic is being
dropped - just not logged.

3750 running Adv IP Services...
interface GigabitEthernet1/0/25
switchport access vlan 701
switchport mode access
ip access-group TEST in

ip access-list extended TEST
deny icmp any any log
permit ip any any log

ip access-list log-update threshold 1

"show access-lists hardware counters" does show drops and I cant ping
through this interface with the ACL applied. It just wont log any ACE
entry matches.

Cheers
Kent.

Posted by on May 15, 2008, 3:49 am
If you were  Registered and logged in, you could reply and use other advanced thread options
> Hi all,
> With the below test config I can't seem to generate a single log entry
> from the ACL. Has anyone had experience in logging with port based
> ACL's on the 3750? With the below config the icmp traffic is being
> dropped - just not logged.
>
> 3750 running Adv IP Services...
> interface GigabitEthernet1/0/25
> =A0switchport access vlan 701
> =A0switchport mode access
> =A0ip access-group TEST in
>
> ip access-list extended TEST
> =A0deny icmp any any log
> =A0permit ip any any log
>
> ip access-list log-update threshold 1
>
> "show access-lists hardware counters" does show drops and I cant ping
> through this interface with the ACL applied. =A0It just wont log any ACE
> entry matches.
>
> Cheers
> Kent.

Have you configured logging?

logg buffered <level> ! <-- debugging enables all
no logg console ! <-- I suggest

Post output of sh logg if unsure.





Posted by Kent on May 15, 2008, 9:24 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
On May 15, 5:49 pm, Bo...@hotmail.co.uk wrote:
>
>
>
> > Hi all,
> > With the below test config I can't seem to generate a single log entry
> > from the ACL. Has anyone had experience in logging with port based
> > ACL's on the 3750? With the below config the icmp traffic is being
> > dropped - just not logged.
>
> > 3750 running Adv IP Services...
> > interface GigabitEthernet1/0/25
> > switchport access vlan 701
> > switchport mode access
> > ip access-group TEST in
>
> > ip access-list extended TEST
> > deny icmp any any log
> > permit ip any any log
>
> > ip access-list log-update threshold 1
>
> > "show access-lists hardware counters" does show drops and I cant ping
> > through this interface with the ACL applied. It just wont log any ACE
> > entry matches.
>
> > Cheers
> > Kent.
>
> Have you configured logging?
>
> logg buffered <level> ! <-- debugging enables all
> no logg console ! <-- I suggest
>
> Post output of sh logg if unsure.

Yes.

Similar ThreadsPosted
802.1X Port-Based Authentication April 13, 2005, 11:03 am
Port based security September 10, 2006, 7:07 pm
route based on destination port August 18, 2005, 8:17 am
TCP/UDP port or protocol-based routing February 6, 2006, 3:38 pm
Different Rate Limits per Port based on IP? May 28, 2006, 12:20 pm
CBOS 675/678 2.4.8 Port Logging the WAN via MS May 30, 2006, 9:25 pm
675/678 CBOS 2.4.8 Port Logging the WAN via MS May 30, 2006, 11:21 pm
Policy routing based on destination port (layer4) January 11, 2006, 12:02 pm
Cisco Announces Industry's First Network-Based, Standards- Based Rapid Channel-Change..... December 26, 2006, 11:36 am
3750 port monitor ? doesn't exist ? June 23, 2005, 1:07 pm

other useful resources:
The Federal Communications Commission (FCC)
Telecommunications Industry Association
Electronic and Software Security Products and Services
International Telecommunication Union

Custom CGI Perl and PHP programming by 1-Script.com

Contact Us | Privacy Policy
The site map in XML format XML site map