Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements
Step-by-Step Configuration and Troubleshooting Best Practices for the NGFW, NGIPS and AMP Technologies A Visual Guide to the Cisco Firepower Threat Defense (FTD)
Community Member

zone-based fireall class-map access-list with 'log' not supported...

I'm using IOS (c3845-advipservicesk9-mz.124-15.T3) zone-based firewall on a 3845 router and when I enable logging on an extended access list (permit ip any any log) that I have applied to a class-map, I get the following message:

"class-map my_cl_map : access-list with 'log' not supported, pls remove 'log' from access-list otherwise class-map my_cl_map will not work properly"

Any ideas what this means? If I apply permit any any log again, it will take it. But what are the consequences?

Relevant config:

class-map type inspect match-all my_cl_map

match class-map protocols

match access-group name my_acl

ip access-list extended my_acl

permit icmp any any

permit tcp host 192.168.1.1 any eq 1022

permit tcp host 192.168.1.1 any eq 513

permit tcp host 192.168.1.1 any eq 514

permit ip any any log

6 REPLIES
Community Member

Re: zone-based fireall class-map access-list with 'log' not supp

why are you entering a "permit ip any any" in the first place? you first four lines are not even needed if you need the last line in the acl. aren't you trying match on specific traffic?

Community Member

Re: zone-based fireall class-map access-list with 'log' not supp

I'm trying to capture what else is needed by doing "permit ip any any log". However, that's besides the point. Do you know why "log" in access lists applied to class-maps not allowed?

Community Member

Re: zone-based fireall class-map access-list with 'log' not supp

the acl is there to identify traffic for the policy, nothing else. you can bind another acl on the interface if you need to identify traffic using the log option

Community Member

Re: zone-based fireall class-map access-list with 'log' not supp

In other words, you have no idea what ""class-map my_cl_map : access-list with 'log' not supported, pls remove 'log' from access-list otherwise class-map my_cl_map will not work properly" means.

Community Member

Re: zone-based fireall class-map access-list with 'log' not supp

I know what you mean. I would like to see log of deny/allow traffic. I have the same problem.

Community Member

Re: zone-based fireall class-map access-list with 'log' not supp

In other words you don't understand english too well.

"the acl is there to identify traffic for the policy, nothing else. "

Identifying traffic with an ACL using a log option isn't going to identify the traffic correctly. If you want to see what's dropped, use the "drop log" in the policy-map for class class-default.

465
Views
0
Helpful
6
Replies
CreatePlease to create content