cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
450
Views
1
Helpful
3
Replies

Best ACL for internet facing port

CiscoPurpleBelt
Level 6
Level 6

What is the best way to create an ACL to be used on an internet facing edge port to keep the logs down when packets are denied from devices not permitted according to the ACL? Is there anyway to hide the public IP from the internet?

1 Accepted Solution

Accepted Solutions

Philip D'Ath
VIP Alumni
VIP Alumni
Don't use the "log" keyword for "deny" entries, and you wont get logging entries.

View solution in original post

3 Replies 3

Philip D'Ath
VIP Alumni
VIP Alumni
Don't use the "log" keyword for "deny" entries, and you wont get logging entries.

Thanks. I know some people keep adding suspect/bad IPs to a deny statement in a ACL which then gets to be very long. I want to keep track of what is going on but yes the log will get pounded.

Thanks. I know some people keep adding suspect/bad IPs to a deny statement in a ACL which then gets to be very long. I want to keep track of what is going on but yes the log will get pounded.

 

Review Cisco Networking products for a $25 gift card