04-29-2022 07:33 PM
I append the new acl (number "9681") into existing ACL "ACL-AVCSS-in-3" (The ACL was applied in TenGigabitEthernet1/1/4 and TenGigabitEthernet1/1/4) on Apr 27 17:44:50. However, the track "%TRACK-6-STATE: 1 ip sla 1 state Up -> Down" and %TRACK-6-STATE: 2 ip sla 2 state Up -> Down was prompted unexpectedly. Please help to open a tech case to CISCO to check if it is a bug or abnormal in our devices.
04-29-2022 08:53 PM
Provide more information, what is the device model ? what IOS Code ?
until we see what is that ACL content and how the track configured. ?
show ip sla configuration x
show track
show ip sla statistics
05-03-2022 07:02 PM - edited 05-05-2022 02:47 AM
Please find the requested details.
. WS-C4500X-32
2. cat4500e-universalk9.SPA.03.11.04.E.152-7.E4.bin
3. ACL and track SLA are attached.
04-29-2022 09:06 PM
This is my end client I will collect relevant information and get back to you.TIA
04-30-2022 01:02 AM
Hello
@AzharMuhammad05932 wrote:
I append the new acl (number "9681") into existing ACL "ACL-AVCSS-in-3" (The ACL was applied in
Make sure you are not negating the HSRP multicast hellos = 224.0.0.2 or 224.0.0.102
permit ip host 224.0.0.2 any
permit ip any host 224.0.0.2
permit ip host 224.0.0.102 any
permit ip any host 224.0.0.102
permit udp any eq 1985 any
permit udp any any eq 1985
04-30-2022 02:39 AM - edited 05-03-2022 07:16 PM
Not the ACL number but ACE number is 9681.
number "9681"
Max number is 2699 so I think that this ACL cause issue with not it permit deny but it number.
why you select this number ??
05-05-2022 12:15 AM
is there any document /link for this that Cisco recommended?
05-05-2022 05:02 AM
cisco doc. for what the number of ACE and/or ACL ?
05-05-2022 05:02 AM - edited 05-05-2022 05:04 AM
cisco doc. for what the number of ACE and-or ACL ?
no need doc.
show cpu
give you detail if this issue from CPU high utilize
05-03-2022 07:18 PM
this huge ACE number need memory and CPU, and since IP SLA is process by SW so there is big chance that your memory and CPU is high utilize and hence some IP SLA is not process as fast it send/receive and router assume it failed.
try reduce these ACL line.
05-04-2022 12:45 AM
if you still struggling with that issue try DEBUG CONDITION ON that interface or SLA even better if your debugging Track that object will show you exactly what is happenning if there is huge debbugging just copy it to somewhere like NOTEPAD then go through that. you will find out what is exactly causing that flapping your SLA.
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: