ACL Logging

ACL logs can provide insight into permitted and denied network traffic.

If an ACL rule matches a packet, the software generates a syslog entry and an SNMP trap and starts a five-minute timer. The timer keeps track of all packets that match the ACL entries. After five minutes, the software generates a syslog entry reporting the matches.

Note the following details:

  • If the packet rate is high—exceeding the CPU processing rate—the packet count may be inaccurate.
  • If there are no matches within the five-minute timer interval, the timer stops, restarting with the next match.
  • The timer for logging packets denied by MAC ACLs is a different timer from the ACL logging timer.
  • When an ACL filter with logging is applied to an interface or LAG or selective port or at VLAN level, a syslog entry is generated whenever the filter matches an ACL rule, whether it is set to permit or deny. If a new ACL is applied to the same interface or LAG, syslog entries are generated for the new ACL filter. After a few seconds, the software generates a single syslog entry for the previously applied ACL once.