Your access list as posted should write to syslog a log message for all data packets whose source port is TCP 443. If that is your objective then this should work. But I question whether this is really the optimum way to do it. For one thng this will not record the beginning of the TCP 3 way handshake, but will record all of the data packets in the data stream with an individual log record of each packet. I would suggest that a more efficient way to identify that traffic occurred without the volume of log records would be like this:
access-list 106 permit tcp any eq 443 any established
access-list 106 permit tcp any eq 443 any log
this will permit the data traffic without creating log records for each packet and will create a log record for the beginning of the TCP session.
I would also suggest that you might be more interested in outbound traffic where the destination port was 443. Adding these lines to the access list would do this:
access-list 106 permit tcp any any eq 443 established
access-list 106 permit tcp any any eq 443 log
this will permit data traffic to destination port TCP 443 without log records for each data packet and will permit establishment of the TCP session and log the event.
Pavlo is pointing you in the right direction. The access list will write records into syslog. It then becomes a question of which destinations you send syslog to. You can send syslog to one or several destinations (and there is not any destination to which you are required to send syslog). So if you do not have a reliable syslog server do not activate syslog to a remote host. You would want to send syslog to the logging buffer as Pavlo suggests (and you probably want to make the logging buffer larger than the default 4K). You could also send syslog to the console or to terminal monitor. But your request to see it with show log would be looking at logging buffered.
We are pleased to announce availability of Beta software for 16.6.3. 16.6.3 will be the second rebuild on the 16.6 release train targeted towards Catalyst 9500/9400/9300/3850/3650 switching platforms. We are looking for early feedback from custome...