cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
977
Views
0
Helpful
2
Replies

Debug an ACL

cdelafuente31
Level 1
Level 1

Hello,

I've configured an ACL in a BVI interface an now is working as intended. But I would like to know which access-list statement matchs with the traffic flowing through the interface.

I've tried with the "debug ip packet <access-list>" but it doesn't show the traffic denied.

Regards,

1 Accepted Solution

Accepted Solutions

adamclarkuk_2
Level 4
Level 4

Try adding a log to the end of the ACL, this should force a punt to the CPU.

debug ip packet only shows process switched traffic.

The other "drastic" measure is to turn off cef, but I dont recommend doing that.

View solution in original post

2 Replies 2

adamclarkuk_2
Level 4
Level 4

Try adding a log to the end of the ACL, this should force a punt to the CPU.

debug ip packet only shows process switched traffic.

The other "drastic" measure is to turn off cef, but I dont recommend doing that.

The ACL does what I want. The problem is the 5 minute interval between statistics.

Thank you very much.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card