cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
373
Views
0
Helpful
2
Replies

6500 access-list not logging

hakbar
Level 1
Level 1

I am not seeing log entries for the 6500 access-list although the traffic is being blocked by it.

Please see the attached file that has sh run and sh access-list etc.

Regards

Hammad

2 Replies 2

Hello Krishn:

Thanks for the message. I am still having problem with the logging:

Here is my current configuration:

SW-INET01-A3-TC1# sh run | begin mls

mls ip multicast flow-stat-timer 9

no mls flow ip

no mls flow ipv6

mls rate-limit unicast ip icmp unreachable acl-drop 0

no mls acl tcam share-global

mls cef error action freeze

!

interface GigabitEthernet1/1

description Link to SunGard via Packeteer

bandwidth 71680

ip address 213.212.74.82 255.255.255.252

ip access-group Inet_to_TC1 in

logging ip access-list cache in

speed 1000

duplex full

spanning-tree portfast

spanning-tree bpdufilter enable

end

When I do a show access-list the results have not changed i.e. I only see hits against permit statements. I do not get any hits against permit statements which use the established parameter.

Any idea why this is happening.