cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
605
Views
0
Helpful
1
Replies

ACL hit counts on 6509 not showing...

RoyalEF
Level 1
Level 1

Our syslog servers are in a subnet attached only to our core router... no other path to them. They are collecting syslog messages (udp 514) from all over our network. We log over a gig per day.

The syslog VLAN has an ACL applied out.

The lines permitting any host to hit the syslog server for udp eq syslog shows no hits at all.

Are there conditions that would preclude hits from registering? I can't find any other ACL lines prior to these entires that would permit these specific packets through and there is a "deny ip any any" at the end of the list. Other ACls in the list shows up to millions of hits, so I know they are functioning and in use.

I don't understand why they aren't showing up in the hit counts?!

1 Reply 1

gskhanna
Level 1
Level 1

The 6500 does acl blocking in programmable hardware asic modules. The hitcount does not show up properly or acurately.

It only shows like 100th of what the real hits are.

'When you enter the show ip access-list command, the match count displayed does not include packets processed in hardware. '

http://www.cisco.com/en/US/products/hw/switches/ps708/products_configuration_guide_chapter09186a00801609f6.html