Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

trying to debug an ACL on PIX

I would like to setup an ACL then use a "debug packet" type command to observe certain traffic on my PIX 515e. I have used this technique many times with IOS routers but the PIX just doesn't behave the same way. As soon as I give the "logging monitor debug" I am swamped with all sorts of info concerning other operations of the PIX like denied inbound packets, NAT events, TCP connections established and so on. How can I get the PIX to show me ONLY the traffic defined by my ACL and NOTHING else?



Cisco Employee

Re: trying to debug an ACL on PIX

Debugging on the PIX will certainly give you a ton of information. With the PIX you can either use the "capture" command to capture all traffic based on an ACL (which can then even be saved off in Sniffer format, very useful), or in 6.3 code you can add a log keyword to the end of the access-list command.

See for details, the default logging level of ACL lines is informational, so if you do "logging monitor info" then you should see these and not get all the other stuff you get at debug level.

CreatePlease to create content