Enabling ACL Logging
For an ACL to generate a syslog entry, match statements to be logged must contain the log keyword, and logging must be enabled for the ACL when it is bound to an interface, LAG, VLAN, or selective ports of a VLAN with the keywords logging enable included in the binding command.
Perform the following steps to configure ACL logging.
- Enter global configuration mode.
- Enter configuration sub-mode for a new or existing ACL.
- To configure an IPv4 ACL, use the appropriate
ip access-listcommand followed by the name or ID.device(config)# ip access-list extended v4track device(config-ipacl-v4track)#
- To configure an IPv6 ACL, use the
ipv6 access-listcommand followed by the name or ID.device(config)# ipv6 access-list v6track device(config-ipv6-access-list v6track)#
- To configure a MAC ACL, use the
mac access-listcommand followed by the name.device(config)# mac access-list mactrack device(config-macl-mactrack)#
- To configure an IPv4 ACL, use the appropriate
- Create or update ACL filter
statements with the log keyword to indicate which
matches should be included in the syslog. The following example configures logging for an IPv4 extended ACL permit action.
device(config)# ip access-list extended v4track device(config-ext-ipacl-vtrack)# permit host 10.157.22.26 any log
The following example configures logging for an IPv6 ACL permit action.device(config)# ipv6 access-list v6track device(config-ipv6-access-list v6track)# permit ipv6 host 10.158.10.10 any log
The following example configures logging for a MAC ACL deny action. - Enable logging for filtered packets on a specific port, a set of ports, a LAG, or
a VLAN.
The following example enables logging on ports 1/1/1 and 1/1/3 for the MAC ACL mactrack.
device(config-macl-maclog)#interface ethernet 1/1/1 device(config-if-e1000-1/1/1)# mac access-group mactrack in logging enable device(config-if-e1000-1/1/1)# interface ethernet 1/1/3 device(config-if-e1000-1/1/3)# mac access-group mactrack in logging enable device(config-if-e1000-1/1/3)# end device#
The following example binds an IPv6 ACL to a LAG.device# configure terminal device(config)# interface lag 46 device(config-lag-if-lg46)# ipv6 access-group v6track in logging enable device(config-lag-if-lg46)# exit device(config)#
The following example binds an IPv4 ACL to a VLAN.device# configure terminal device(config)# vlan 222 by port device(config-vlan-222)# vlan 222 by port device(config-vlan-222)# interface ve 222 device(config-vlan-222)# ip access-group v4track in logging enable device(config-vlan-222)# exit
The following example binds acl1 to incoming traffic on selective ports in VLAN 10 (LAG 1 ports and Ethernet port 1/1/1) and enables logging for the ACL on the same interfaces.