ACL logging on N1KV issue
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-30-2013 07:11 AM - edited 03-07-2019 11:24 AM
We have an ACL created and applied to a port-profile on N1KV
We are getting hits on this ACL, but the actual denies are not getting logged on VSM or our syslog server. If we check on the VEM we can see the details while the flow is active. Example:
Hovewer, on VSM, it shows nothing, but the hit counter increasing:
VEM acllog config:
VSM acllog config (note, we tried to change acllog level from default 2 to 6 using "loggong level acllog 6" to no avail):
What do we need to do to start logging ACL events locally and to the external syslog?
Thanks.
- Labels:
-
Other Switching
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-15-2013 11:42 AM
Hello Dmitri,
The Cisco Nexus 1000v sources ACL Logs from the VEMs themselves. Therefore, if your syslog server is, for example, Cisco LMS, it is configured to see syslogs from one IP - that of the VSM VIP for the N1KV switch.
You will need to setup a syslog server that can view syslogs sourcing from the IPs of the VEMs, which are the IPs of your ESXi hosts.
