Warning message

  • Cisco Support Forums is in Read Only mode while the site is being migrated.
  • Cisco Support Forums is in Read Only mode while the site is being migrated.

ACL counters issue

Answered Question
Apr 3rd, 2012
User Badges:


I have 2911 router with 15.0 IOS + security + data. The problem is in ACL hit logging. Even if i applied statement "permit ip any any log" on the interface, counters would not match anything.

Correct Answer by Vasileios Boulo... about 5 years 4 months ago


Did you search for the possibiltiy of a bug?

I have involved to a problem with an Access-list that denied all and was solved with a new IOS


Hope that helps,


  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 5 (1 ratings)
Edison Ortiz Tue, 04/03/2012 - 07:57
User Badges:
  • Super Bronze, 10000 points or more
  • Hall of Fame,

    Founding Member

Can you provide configs and example of exactly what you are seeing?

Vyacheslav_Maliev Tue, 04/03/2012 - 08:22
User Badges:

Yes, here you are:

interface GigabitEthernet0/0

ip address

ip access-group test_acl in

ip flow ingress

ip flow egress

duplex auto

speed auto

ip access-list extended test_acl

  permit ip any any log

i am seeing:

#show interfaces gigabitEthernet 0/0

GigabitEthernet0/0 is up, line protocol is up

  Hardware is CN Gigabit Ethernet, address is c471.fec5.89f8 (bia c471.fec5.89f8)

  Internet address is

  MTU 1500 bytes, BW 100000 Kbit/sec, DLY 100 usec,

     reliability 255/255, txload 1/255, rxload 1/255

  Encapsulation ARPA, loopback not set

  Keepalive set (10 sec)

  Full Duplex, 100Mbps, media type is RJ45

  output flow-control is XON, input flow-control is XON

  ARP type: ARPA, ARP Timeout 04:00:00

  Last input 00:00:10, output 00:00:00, output hang never

  Last clearing of "show interface" counters never

  Input queue: 0/75/0/0 (size/max/drops/flushes); Total output drops: 35

  Queueing strategy: fifo

  Output queue: 0/40 (size/max)

  5 minute input rate 186000 bits/sec, 10 packets/sec

  5 minute output rate 27000 bits/sec, 14 packets/sec

     418641389 packets input, 3158351856 bytes, 0 no buffer

     Received 69630 broadcasts (0 IP multicasts)

     0 runts, 0 giants, 0 throttles

     0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored

     0 watchdog, 66277 multicast, 0 pause input

     439197818 packets output, 803260124 bytes, 0 underruns

     0 output errors, 0 collisions, 0 interface resets

     0 unknown protocol drops

     0 babbles, 0 late collision, 0 deferred

     2 lost carrier, 0 no carrier, 0 pause output

     0 output buffer failures, 0 output buffers swapped out

#sh ip access-lists

Standard IP access list RADMIN

    10 permit, wildcard bits (12 matches)

Extended IP access list test_acl

    10 permit ip any any log

Edison Ortiz Tue, 04/03/2012 - 09:26
User Badges:
  • Super Bronze, 10000 points or more
  • Hall of Fame,

    Founding Member

Unable to duplicate:

System image file is "flash0:c2900-universalk9-mz.SPA.151-1.T.bin"

ip access-list extended acl-in

permit ip any any log

interface GigabitEthernet0/0

ip address

ip access-group acl-in in

duplex auto

speed auto


Type escape sequence to abort.

Sending 5, 100-byte ICMP Echos to, timeout is 2 seconds:


Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/1 ms


%SEC-6-IPACCESSLOGDP: list acl-in permitted icmp -> (0/0), 1 packet 

Extended IP access list acl-in

    10 permit ip any any log (9 matches)

Peter Paluch Wed, 04/04/2012 - 06:28
User Badges:
  • Cisco Employee,

Hi Vyacheslav,

IP CEF is activated globally by default indeed, but on ISR and ISR G2 routers, CEF is purely software-based. Counters on ACLs are not incremented if they are processed in hardware, which should not be the case here.

Best regards,



This Discussion