cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
123
Views
0
Helpful
2
Replies

Problem ACL with SYSLOG server

Muawiya Awadat
Community Member

Hi ALL,

I have issues in access list. I configure access list in switch for syslog massage with port 1514 and set in VLAN outbound but not match

IOS version (X86_64BI_LINUX_L2-ADVENTERPRISEK9-M), Version 17.12.1

Extended IP access list SNMP&&AAA&&SSH
10 permit udp host 10.10.30.4 eq 1812 host 10.10.10.4 (6 matches)
20 permit udp host 10.10.30.4 eq 1813 host 10.10.10.4
30 permit udp host 10.10.30.4 host 10.10.10.4 eq snmp (20390 matches)
40 permit tcp host 10.10.30.4 any eq 22 (30 matches)
50 deny udp any eq 1812 any
60 deny udp any eq 1813 any
70 deny udp any any eq snmp (2 matches)
80 deny tcp any any eq 22
90 permit ip any any (15322 matches)
Extended IP access list SYSLOG
10 permit udp host 10.10.10.4 host 10.10.30.4 eq 1514
20 deny udp any host 10.10.30.4 eq 1514
30 deny udp any any eq syslog
40 permit ip any any

interface Vlan103
ip address 192.168.103.5 255.255.255.0
ip access-group SNMP&&AAA&&SSH in
ip access-group SYSLOG out
end

2 Replies 2

Giuseppe Larosa
Hall of Fame
Hall of Fame

Hello @Muawiya Awadat ,

syslog messages are sent out the SVI vlan103 in two cases :

a) the VLAN103 is the OSI L3 interface towards syslog server IP address 10.10.30.4

b) if vlan103 SVI is configured as source for sending syslog messages

from the other ACL that is applied inbound and not outbound we can see that trafffic from host 10.10.30.4 to IP address 10.10.10.4 is seen with a lot of matches for SNMP

However, what is the outgoing interface to reach the syslog server on the local switch ?

check with

show ip route 10.10.30.4

on the switch

Hope to help

Giuseppe

 

Hello @Giuseppe Larosa 

show ip route 10.10.30.4    out from vlan 103 

I set source syslog server sent from loopback 0

Thank you