Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

How does the router count "matched" packets on an ACL?

I have an ACL applied to the Internet facing serial connection of a 7204. I have deny statements in place blocking IP for a couple of class C addresses that hit us with heavy spam. Before placing the ACL we had far more inbound spam messages than are reflected by the counters on the ACL. Does anyone no why the number of matches on the ACL would be so much less? Is a match counted against every packet that comes through the interface and meets the criteria of an ACL statement?

Cisco Employee

Re: How does the router count "matched" packets on an ACL?

Only those ackets will be counted which exactly meets the criteria defined in the access-lists & in the direction in which the acl is applied. For exa

access-list 101 permit tcp any any eq www

and if it applied inbound, it will count all the http packets which comes in via that interface. So now tune acl accordingly