06-25-2008 01:21 PM - edited 03-11-2019 06:05 AM
Show access-list command
access-list incoming line 3 extended permit ip object-group test object-group test1 log informational interval 300
Solved! Go to Solution.
06-26-2008 11:30 PM
Yes it should show the hit count, even if 0. The only thing that doesn't show a hit count is the object-group line as this is expanded below to show the indivdual entries.
so (and forgive me if this misses the point) you may be looking at the wrong line in the command results. An example of what I would have expected is below - if your output doesn't match it then I would be interested to see the relevant snippets of your config and 'show' output.
object-group service WEBPORTS tcp
port-object eq 80
port-object eq 443
access-list incoming permit tcp any any object-group WEBPORTS
show access-list incoming
...would show something along the lines of.
access-list incoming line 1 permit tcp any any object-group WEBPORTS
access-list incoming line 1 permit tcp any any eq http (hitcnt=0)
access-list incoming line 1 permit tcp any any eq https (hitcnt=0)
06-26-2008 03:08 AM
Hello Kr,
If you're using show access-list xxx and not seeing a hit count then the simple answer is likely to be that the packets are not matching the access-list entry.
Is NAT involved? Perhaps the source or destination address is not as you would expect.
06-26-2008 04:57 AM
Hi,
Atleast it should how hitcount=0 right ?
06-26-2008 11:30 PM
Yes it should show the hit count, even if 0. The only thing that doesn't show a hit count is the object-group line as this is expanded below to show the indivdual entries.
so (and forgive me if this misses the point) you may be looking at the wrong line in the command results. An example of what I would have expected is below - if your output doesn't match it then I would be interested to see the relevant snippets of your config and 'show' output.
object-group service WEBPORTS tcp
port-object eq 80
port-object eq 443
access-list incoming permit tcp any any object-group WEBPORTS
show access-list incoming
...would show something along the lines of.
access-list incoming line 1 permit tcp any any object-group WEBPORTS
access-list incoming line 1 permit tcp any any eq http (hitcnt=0)
access-list incoming line 1 permit tcp any any eq https (hitcnt=0)
06-27-2008 10:34 AM
Thanks for information !!!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide