Logging ACL Rules

To enable syslog for IPv4 access-lists, add the keyword log to an ACL rule, and enable logging on the interface to which the access-list is applied with the acl-logging command as shown in the following example.

device# configure terminal
device(config)# permit tcp host 18.1.1.3 host 19.1.1.2 log
device(config)# interface ethernet 1/4/4
device(config-if-e10000-1/4/4)# acl-logging

To enable syslog for IPv6 access lists, enter the command logging-enable as part of the access list in access-list configuration sub-mode, and include the keyword log as part of the ACL rule as shown in the following example.

device# configure terminal
device(config)# ipv6 access-list acl1
device(config-ipv6-access-list acl1)# logging-enable
device(config-ipv6-access-list acl1)# permit ipv6 any host 19::2 log