Showing results for 
Search instead for 
Did you mean: 

Community Helping Community


ME3600 ACL out does not work or does not seem to work


interface GigabitEthernet0/1
 description Trianel Krefelderstr.
 no switchport
 bandwidth 1000000
 ip vrf forwarding trianel
 ip address
 no ip proxy-arp
 ip access-group trianel-flexpool-btc-zugriff-in in
 ip access-group trianel-flexpool-btc-zugriff-out out
 ip ospf network point-to-point
 load-interval 30
 no cdp enable
 no lldp transmit

sw04000154#sh ip access-lists trianel-flexpool-btc-zugriff-out
Extended IP access list trianel-flexpool-btc-zugriff-out
    10 permit ip
    20 permit ip
    30 permit ip host
    40 permit ip host
    50 permit ip host
    59 permit icmp reflect relexive
    60 permit ip reflect reflect_trianel-flexpool-btc-zugriff
    90 deny ip any log-input
    100 permit ip any any

sw04000154#sh ip access-lists trianel-flexpool-btc-zugriff-in
Extended IP access list trianel-flexpool-btc-zugriff-in
    10 permit ip
    20 permit ip
    30 permit ip host
    40 permit ip host
    50 permit ip host
    59 evaluate relexive
    60 evaluate reflect_trianel-flexpool-btc-zugriff
    70 permit icmp
    90 deny ip any (18 matches)
    100 permit ip any any (2511 matches)


The outgoing ACL seems not to work as counters does not increase.

The reflexive ACL is still empty when i make a ping from -->


As so the ACL does not increase at the "evaluate" lines.


By the way, I don t trust the ACL in Counters, because 2511 matches after 4 hours with ~100 Mbit... I guess this can't be right to...:
 sw04000154#sh int gi0/1
  30 second input rate 2051000 bits/sec, 1182 packets/sec
  30 second output rate 14006000 bits/sec, 1778 packets/sec

Well, the routing uplink to core is mpls/bgp vpnv4 (ospf as underlying in global routing context).


The Downlink side at gi0/1 is not under my administration, and i want to disallow some outgoing traffic to.



So, has somebody an idea, whats going wrong?


thanks a lot



Everyone's tags (3)
CreatePlease to create content
Content for Community-Ad