Port based ACL logging 3750

Unanswered Question
May 14th, 2008

Hi,

With the below test config I can't seem to generate a single log entry from the ACL? Has anyone had experience in logging with port based ACL's? The icmp traffic is being dropped - just not logged.

3750 running Adv IP Services

interface GigabitEthernet1/0/25

switchport access vlan 701

switchport mode access

ip access-group TEST in

ip access-list extended TEST

deny icmp any any log

permit ip any any log

ip access-list log-update threshold 1

"show access-lists hardware counters" does show drops.

Cheers

Kent.

I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
kent.plummer Tue, 05/20/2008 - 09:17

The TAC confirms that ACL logging is not supported for an IP ACL applied to a layer 2 switchport. Logging only works when applied to a switchport in routed mode or an SVI.

Kent.

Actions

This Discussion