cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1053
Views
5
Helpful
4
Replies

Counters in ACL lines

sSiDs
Level 1
Level 1

Good day team!

I have read this thread https://community.cisco.com/t5/switching/acl-not-showing-matches/td-p/997343

That matches couldn't be visible.

But... i did not find any information about  - does syntax or rules with tcp\udp\ip should be somehow lifehacked written to see the matches.

I have splunk installed and could see it there, but in our fast reality better be watch in second that traffic passing through the ACL line

1 Accepted Solution

Accepted Solutions

as i thought))

 

platform is c9300-48P

View solution in original post

4 Replies 4

balaji.bandi
Hall of Fame
Hall of Fame

Not sure what is the issue, the example provide allow syslog ACL to allow.

 

what are you looking ? ACL Logs to Splunk ?

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

I see logs in Splunk, i have configured looging host

 

what i want to see  - it is (matches) at the and of ACL line

 

here is an example:

Extended IP access list Lan97
5 permit icmp 192.168.97.0 0.0.0.255 any
10 permit tcp 192.168.97.0 0.0.0.255 host 192.168.1.100 eq smtp
20 permit udp any any eq bootpc
30 permit udp any any eq bootps (57 matches)
50 permit ip 192.168.97.0 0.0.0.255 any (8240 matches)
70 permit tcp 10.0.0.0 0.255.255.255 192.168.97.0 0.0.0.255 established
100 deny ip any 192.168.0.0 0.0.255.255 (9960 matches)
110 deny ip any 172.16.0.0 0.0.255.255 (235 matches)
120 deny ip any 10.0.0.0 0.255.255.255 (3 matches)

how to know does matches will be visible or not when adding line?)

Or it is up to switch to decide where to process ACL  - hw or sw? write?

Hello @sSiDs ,

>>

how to know does matches will be visible or not when adding line?)

Or it is up to switch to decide where to process ACL - hw or sw? write?

 

it is a question of platform hardware and in some case of IOS version if you will be able to see hit counts per ACL line or not.

You can try and see the results. But there is not a way to write ACL statements that will cause the hit count to be updated or not.

 

Hope to help

Giuseppe

 

 

 

as i thought))

 

platform is c9300-48P

Review Cisco Networking for a $25 gift card