cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
983
Views
0
Helpful
2
Replies

Debug an ACL

cdelafuente31
Level 1
Level 1

Hello,

I've configured an ACL in a BVI interface an now is working as intended. But I would like to know which access-list statement matchs with the traffic flowing through the interface.

I've tried with the "debug ip packet <access-list>" but it doesn't show the traffic denied.

Regards,

1 Accepted Solution

Accepted Solutions

adamclarkuk_2
Level 4
Level 4

Try adding a log to the end of the ACL, this should force a punt to the CPU.

debug ip packet only shows process switched traffic.

The other "drastic" measure is to turn off cef, but I dont recommend doing that.

View solution in original post

2 Replies 2

adamclarkuk_2
Level 4
Level 4

Try adding a log to the end of the ACL, this should force a punt to the CPU.

debug ip packet only shows process switched traffic.

The other "drastic" measure is to turn off cef, but I dont recommend doing that.

The ACL does what I want. The problem is the 5 minute interval between statistics.

Thank you very much.

Review Cisco Networking products for a $25 gift card