cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
477
Views
0
Helpful
2
Replies

Anything I can do about "access-list logging rate-limited or missed packet"

vitro25
Level 1
Level 1

I get a lot of these messages on my syslog server from a Cisco 7204. What can I do about this? I really want to log everything.

2 Replies 2

thomas.chen
Level 6
Level 6

Some packet-matching logs were missed because the access list log messages were rate limited, or no access list log buffers were available. Recommended Action: No action is required.

The problem here is that your switch is receiving too much traffic at the same time and it is not able to log every packet. The reason why it doesn't log them is to protect itself from crashing, because it takes processor usage to handle the ACLs logs.

Now we have two solutions for this log message:

1) If you want to disable the messages you need to erase the log keyword from the ACL statements. (the keyword log :Logs a packet when it matches the ACE)

2)Increasing the amount of packets log (but that will decrease the performance of your 3750)

Thanks for the response. I have been eliminating non-essential logging. However I am still receiving the messages. I need to log as much inbound information as possible. How do I perform option #2?

Review Cisco Networking for a $25 gift card