Configuration Notes for ACL Logging

Before configuring ACL logging on your device, consider the following configuration notes for IPv4, IPv6, and MAC ACLs.

  • ACL logging is a CPU-intensive feature intended for debugging purposes. RUCKUS recommends that you disable ACL logging after the debug session is over.
  • To maintain maximum performance, log only specific filters.
  • When ACL logging is enabled, packets sent to the CPU are automatically rate-limited to prevent CPU overload.
  • You can enable ACL logging on physical interfaces and VLANs.
  • If you remove an egress ACL with rules enabled for logging, although new packets are not logged, previous logs will be in the syslog when the sample timer expires.
  • The log count may not be accurate for broadcast traffic or for unknown unicast traffic.
  • On RUCKUS ICX 7150, RUCKUS ICX 7550, RUCKUS ICX 7650, RUCKUS ICX 7750, and RUCKUS ICX 7850 devices, ACL logging is not supported for ACLs applied to outbound traffic.
  • In a rule that includes one or more of the following parameters, the log keyword is ignored:
    • dscp-matching
    • dscp-marking
    • 802.1p-priority-matching
    • 802.1p-priority-marking
    • 802.1p-and-internal-marking
  • ACL logging is not supported for dynamic ACLs with MAC authentication or 802.1X authentication enabled.
  • ACL logging is supported for ACLs that are applied to network management access features such as Telnet, SSH, and SNMP.