cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
476
Views
0
Helpful
3
Replies

access list permit matching

Muhammed AKYUZ
Level 1
Level 1

on 3560

there is access list and on access list there are permit statements. when i check with show access-list i do not see any matches.. But if i make it deny there are matches... Is there any bug?

Thank you.

3 Replies 3

Jon Marshall
Hall of Fame
Hall of Fame

akyuznet45 wrote:

on 3560

there is access list and on access list there are permit statements. when i check with show access-list i do not see any matches.. But if i make it deny there are matches... Is there any bug?

Thank you.

No there is no bug. Permit statements are dealt with in hardware so you do not see any hits on the acl. However deny statements are also dealt with in hardware usually. Do you have the "log" keyword at the end of the deny statements ?

Jon

I did not understand your comment Marshall. Which one is on the hardware? permit or deny? we are getting only problem permit layer 4 access list.. we do not have matching problem with permit L3 access lists...

Thank you.

Aky,

Jon meant to see/view the matched packets by the access-list.

Even i understood your question in that way first..-:)

Seems you cannot see the access list created when doing a sh access-list rite ?

If its visible in the sh run then it seems to be a problem i never encountered.

Try the command sh access-list 1 (with the no)

If nothing works then it sounds buggy..

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card