ACL Logging Upgrade Considerations
In FastIron 08.0.95 and later releases,
the
acl-logging command
for IPv4 and logging-enable command for IPv6 are replaced by the logging enable command. ACL
logging is configurable only at the binding level and is used in conjunction with
the log keyword at the filter level for
IPv4, IPv6, and MAC ACLs. After upgrade to FastIron 08.0.95 or a later release, the following changes occur if ACL logging is enabled.
- IPv4 ACL: If logging is enabled for an interface before upgrade, then logging will be enabled for all the existing ACLs on the interface to which they are bound to and their ingress and egress directions after the upgrade.
- IPv6 ACL: If logging is enabled for an IPv6 ACL and the interface to which it is bound before upgrade, then logging will be enabled for all bindings of the existing ACLs in both the ingress and egress directions after the upgrade.
- MAC ACL: If MAC filter logging is enabled on global level before upgrade, then log option will get added to all MAC ACL rules after the upgrade. Also, if logging is enabled for a filter group binding to an interface before upgrade, then logging will be enabled for the respective bindings corresponding to the filter group and interface combination in the ingress direction after the upgrade.
Note: On RUCKUS ICX 7150, ICX 7550, ICX 7650, and
ICX 7850 devices, ACL logging is not supported for ACLs applied to outbound traffic.