cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
5767
Views
0
Helpful
4
Replies

ip access-list logging !!!!

mohammed hashim
Level 1
Level 1

hi,

this command "ip access-list logging interval" is global and applied to all ACLs.

is there a way to do it for specific ACLs ?

thanks,

2 Accepted Solutions

Accepted Solutions

julijime
Cisco Employee
Cisco Employee

Hi Mohammed, 

This command cannot be applied to an specific ACL, the interval as you correctly stated applies globally and this is because it will help to minimize the impact the ACL logging has on the CPU load.

HTH

Julio

View solution in original post

Ganesh Hariharan
VIP Alumni
VIP Alumni

Hello Mohammed,

Yes you are right and I agree with Julio as well.

IP access-list logging can be only applicable globaly not for any specific ACL, You have a look on the below link for best practice to apply ACL logging.

http://www.cisco.com/web/about/security/intelligence/acl-logging.html

Hope it Helps..

-GI

View solution in original post

4 Replies 4

julijime
Cisco Employee
Cisco Employee

Hi Mohammed, 

This command cannot be applied to an specific ACL, the interval as you correctly stated applies globally and this is because it will help to minimize the impact the ACL logging has on the CPU load.

HTH

Julio

Ganesh Hariharan
VIP Alumni
VIP Alumni

Hello Mohammed,

Yes you are right and I agree with Julio as well.

IP access-list logging can be only applicable globaly not for any specific ACL, You have a look on the below link for best practice to apply ACL logging.

http://www.cisco.com/web/about/security/intelligence/acl-logging.html

Hope it Helps..

-GI

thanks for reply guys

Hello everyone, My question is not related to running conversation but its related with ACL logs. Please let me know how can i enable logs on running access list.Suppose I have access list there are certail permit /deny statements.Now my manager wants me to configure logs in access list.Please guide me how can i configure.

 

Existingg acl is 

 

permit ip x.x.x.x ip x.x.x.x

requirement is 

permit ip x.x.x.x ip x.x.x.x

If i do above config. will it interrupt my network.What is the best solution to configure logs on running acl.

 

Review Cisco Networking for a $25 gift card