<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco 4500x Viewing VLAN Interface ACL Logging in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-4500x-viewing-vlan-interface-acl-logging/m-p/4995438#M1107900</link>
    <description>&lt;P&gt;Just updated the ACL with to include log-input instead of log and with log-input that should show where the packets come from correct?&lt;/P&gt;</description>
    <pubDate>Fri, 12 Jan 2024 17:01:53 GMT</pubDate>
    <dc:creator>OSUOPT</dc:creator>
    <dc:date>2024-01-12T17:01:53Z</dc:date>
    <item>
      <title>Cisco 4500x Viewing VLAN Interface ACL Logging</title>
      <link>https://community.cisco.com/t5/network-security/cisco-4500x-viewing-vlan-interface-acl-logging/m-p/4995372#M1107892</link>
      <description>&lt;P&gt;Hello I am attempting to figure out an odd Inbound ACL issue where for some reason none of the traffic that is going to a VLAN is not matching any of the subnets (In the case for the two I am testing they are coming through the edge firewall first that I have permitted in the ACL and will only match to a "permit ip any any".&lt;/P&gt;&lt;P&gt;Here is the ACL that I have temporary applied to log traffic running to it.&lt;/P&gt;&lt;P&gt;Extended IP access list "name"&lt;BR /&gt;10 permit ip any any log (14 match)&lt;/P&gt;&lt;P&gt;Is there a way to check and see the source and destination traffic information on the cisco 4500x itself or force it to log and send those type of logs to my syslog?&lt;/P&gt;&lt;P&gt;Here is my current logging setup&lt;/P&gt;&lt;P&gt;logging buffered informational&lt;BR /&gt;logging console informational&lt;BR /&gt;logging monitor informational&lt;/P&gt;&lt;P&gt;ip access-list log-update threshold 10&lt;/P&gt;&lt;P&gt;logging host x.x.x.x&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jan 2024 16:18:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-4500x-viewing-vlan-interface-acl-logging/m-p/4995372#M1107892</guid>
      <dc:creator>OSUOPT</dc:creator>
      <dc:date>2024-01-12T16:18:52Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 4500x Viewing VLAN Interface ACL Logging</title>
      <link>https://community.cisco.com/t5/network-security/cisco-4500x-viewing-vlan-interface-acl-logging/m-p/4995380#M1107893</link>
      <description>&lt;P&gt;Did you add log to end of acl?&lt;/P&gt;
&lt;P&gt;Are this acl is port-acl or vlan acl?&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jan 2024 16:23:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-4500x-viewing-vlan-interface-acl-logging/m-p/4995380#M1107893</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-01-12T16:23:20Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 4500x Viewing VLAN Interface ACL Logging</title>
      <link>https://community.cisco.com/t5/network-security/cisco-4500x-viewing-vlan-interface-acl-logging/m-p/4995382#M1107894</link>
      <description>&lt;P&gt;I have log in the line "10 permit ip any any log". Do I need to add another line to that ACL separately to have it log?&lt;/P&gt;&lt;P&gt;This ACL is applied to a VLAN interface&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jan 2024 16:27:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-4500x-viewing-vlan-interface-acl-logging/m-p/4995382#M1107894</guid>
      <dc:creator>OSUOPT</dc:creator>
      <dc:date>2024-01-12T16:27:12Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 4500x Viewing VLAN Interface ACL Logging</title>
      <link>https://community.cisco.com/t5/network-security/cisco-4500x-viewing-vlan-interface-acl-logging/m-p/4995403#M1107895</link>
      <description>&lt;P&gt;are this ACL apply OUT or IN ?&lt;BR /&gt;MHM&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jan 2024 16:39:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-4500x-viewing-vlan-interface-acl-logging/m-p/4995403#M1107895</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-01-12T16:39:12Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 4500x Viewing VLAN Interface ACL Logging</title>
      <link>https://community.cisco.com/t5/network-security/cisco-4500x-viewing-vlan-interface-acl-logging/m-p/4995405#M1107896</link>
      <description>&lt;P&gt;The ACL is applied IN&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jan 2024 16:41:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-4500x-viewing-vlan-interface-acl-logging/m-p/4995405#M1107896</guid>
      <dc:creator>OSUOPT</dc:creator>
      <dc:date>2024-01-12T16:41:11Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 4500x Viewing VLAN Interface ACL Logging</title>
      <link>https://community.cisco.com/t5/network-security/cisco-4500x-viewing-vlan-interface-acl-logging/m-p/4995412#M1107897</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/587249"&gt;@OSUOPT&lt;/a&gt; use "logging trap &amp;lt;level&amp;gt;" to set syslog logging and obviously the "logging host".&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jan 2024 16:46:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-4500x-viewing-vlan-interface-acl-logging/m-p/4995412#M1107897</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2024-01-12T16:46:12Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 4500x Viewing VLAN Interface ACL Logging</title>
      <link>https://community.cisco.com/t5/network-security/cisco-4500x-viewing-vlan-interface-acl-logging/m-p/4995418#M1107898</link>
      <description>&lt;P&gt;Forgot to include logging trap but I have that set to "logging trap informational" and I do have the logging host set as mentioned in the initial but without the IP set for it&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jan 2024 16:52:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-4500x-viewing-vlan-interface-acl-logging/m-p/4995418#M1107898</guid>
      <dc:creator>OSUOPT</dc:creator>
      <dc:date>2024-01-12T16:52:55Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 4500x Viewing VLAN Interface ACL Logging</title>
      <link>https://community.cisco.com/t5/network-security/cisco-4500x-viewing-vlan-interface-acl-logging/m-p/4995424#M1107899</link>
      <description>&lt;P&gt;use log-input instead of log&lt;BR /&gt;MHM&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jan 2024 16:54:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-4500x-viewing-vlan-interface-acl-logging/m-p/4995424#M1107899</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-01-12T16:54:11Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 4500x Viewing VLAN Interface ACL Logging</title>
      <link>https://community.cisco.com/t5/network-security/cisco-4500x-viewing-vlan-interface-acl-logging/m-p/4995438#M1107900</link>
      <description>&lt;P&gt;Just updated the ACL with to include log-input instead of log and with log-input that should show where the packets come from correct?&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jan 2024 17:01:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-4500x-viewing-vlan-interface-acl-logging/m-p/4995438#M1107900</guid>
      <dc:creator>OSUOPT</dc:creator>
      <dc:date>2024-01-12T17:01:53Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 4500x Viewing VLAN Interface ACL Logging</title>
      <link>https://community.cisco.com/t5/network-security/cisco-4500x-viewing-vlan-interface-acl-logging/m-p/4995445#M1107901</link>
      <description>&lt;P&gt;Yes and also I hope it appear for each source/destination&amp;nbsp;&lt;BR /&gt;what in my mind&amp;nbsp;&lt;/P&gt;
&lt;P&gt;the log is not generate when each packet hit the ACL but when first packet hit the ACL then if same packet same ACL it generate log in specific rate&amp;nbsp;&lt;BR /&gt;I hope when we use log-input we get log for each destination.&lt;BR /&gt;try it and check&amp;nbsp;&lt;BR /&gt;MHM&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jan 2024 17:06:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-4500x-viewing-vlan-interface-acl-logging/m-p/4995445#M1107901</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-01-12T17:06:14Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 4500x Viewing VLAN Interface ACL Logging</title>
      <link>https://community.cisco.com/t5/network-security/cisco-4500x-viewing-vlan-interface-acl-logging/m-p/4995452#M1107902</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/587249"&gt;@OSUOPT&lt;/a&gt; &lt;SPAN&gt;the&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG style="line-height: 1.66em;"&gt;log-input &lt;/STRONG&gt;&lt;SPAN&gt;option will contain the ingress interface and source MAC address information.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The log option would be enough to tell you the source and destination though? example:-&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;*Jan 12 16:53:56.537: %SEC-6-IPACCESSLOGDP: list ACL permitted icmp 192.168.10.2 -&amp;gt; 192.168.10.1 (0/0), 5&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jan 2024 17:07:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-4500x-viewing-vlan-interface-acl-logging/m-p/4995452#M1107902</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2024-01-12T17:07:39Z</dc:date>
    </item>
  </channel>
</rss>

