cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
717
Views
0
Helpful
1
Replies

ACL logging on N1KV issue

We have an ACL created and applied to a port-profile on N1KV

We are getting hits on this ACL, but the actual denies are not getting logged on VSM or our syslog server. If we check on the VEM we can see the details while the flow is active. Example:

vem ACL.jpg

Hovewer, on VSM, it shows nothing, but the hit counter increasing:

vsm ACL.jpg

VEM acllog config:

vem acllog.jpg

VSM acllog config (note, we tried to change acllog level from default 2 to 6 using "loggong level acllog 6" to no avail):

vsm acllog.jpg

What do we need to do to start logging ACL events locally and to the external syslog?

Thanks.

1 Reply 1

Nick Catenacci
Level 1
Level 1

Hello Dmitri,

The Cisco Nexus 1000v sources ACL Logs from the VEMs themselves.  Therefore, if your syslog server is, for example, Cisco LMS, it is configured to see syslogs from one IP - that of the VSM VIP for the N1KV switch. 

You will need to setup a syslog server that can view syslogs sourcing from the IPs of the VEMs, which are the IPs of your ESXi hosts.

Review Cisco Networking for a $25 gift card