Configuring ACL Accounting
If you enable accounting for an ACL, it
applies to all rules in that ACL, including implicit rules.
- To enable ACL accounting for a
configured ACL, use the
enable accountingcommand in IPv4, IPv6, or MAC ACL configuration sub-mode.The following example enables accounting for an IPv4 ACL.The following example enables accounting for an IPv6 ACL.device(config)# ipv6 access-list acl_1pv6 device(config-ipv6-access-list acl_ipv6)# enable accounting
The following example enables accounting for a MAC ACL. - Display the ACL accounting
information using the
show access-list accountingcommand.The accounting statistics are collected every five seconds and synchronized to remote units every one minute.The following example displays a brief accounting summary for ACLs applied inbound to VLAN 333.device# show access-list accounting vlan 333 in brief ACL Accounting Table ========================================================================================================================================================== UnitID: 1 ACL Name: acl_l2 HitCnt: 0 ByteCnt: 0 UnitID: 1 ACL Name: acl_ipv4 HitCnt: 0 ByteCnt: 0 UnitID: 1 ACL Name: acl_ipv6 HitCnt: 0 ByteCnt: 0 UnitID: 2 ACL Name: acl_l2 HitCnt: 0 ByteCnt: 0 UnitID: 2 ACL Name: acl_ipv4 HitCnt: 0 ByteCnt: 0 UnitID: 2 ACL Name: acl_ipv6 HitCnt: 0 ByteCnt: 0 UnitID: 3 ACL Name: acl_l2 HitCnt: 0 ByteCnt: 0 UnitID: 3 ACL Name: acl_ipv4 HitCnt: 0 ByteCnt: 0 UnitID: 3 ACL Name: acl_ipv6 HitCnt: 0 ByteCnt: 0
The following example displays an accounting summary for inbound IPv4 ACLs active on VLAN 333.device# show access-list accounting vlan 333 in ipv4 brief ACL Accounting Table ========================================================================================================================================================== UnitID: 1 ACL Name: mirror_acl_ipv4 HitCnt: 0 ByteCnt: 0 UnitID: 2 ACL Name: mirror_acl_ipv4 HitCnt: 0 ByteCnt: 0 UnitID: 3 ACL Name: mirror_acl_ipv4 HitCnt: 0 ByteCnt: 0
The following example displays summary inbound MAC ACL accounting statistics for VLAN 224.device# show access-list accounting vlan 224 in mac brief ACL Accounting Table ===================================================================================================== UnitID: 1 ACL Name: mirror_acl_l2 HitCnt: 0 ByteCnt: 0 UnitID: 1 ACL Name: mac HitCnt: 1450 ByteCnt: 147144 UnitID: 2 ACL Name: mirror_acl_l2 HitCnt: 0 ByteCnt: 0 UnitID: 2 ACL Name: mac HitCnt: 4581 ByteCnt: 456606 UnitID: 4 ACL Name: mirror_acl_l2 HitCnt: 0 ByteCnt: 0 UnitID: 4 ACL Name: mac HitCnt: 0 ByteCnt: 0
The following example displays detailed inbound MAC ACL accounting statistics for VLAN 224.device# show access-list accounting vlan 224 in mac detail ACL Accounting Table ================================================================================================ ACL Name: mac UnitID: 1 Region: 0 Filter Seq Num: 10 Filter Def: deny any 0000.0000.0088 0000.0000.1111 log HitCnt: 9 ByteCnt: 774 UnitID: 1 Region: 0 Filter Seq Num: 20 Filter Def: permit any any log HitCnt: 1441 ByteCnt: 146370 UnitID: 1 Region: 0 Filter Seq Num: 65001 Filter Def: deny any any HitCnt: 0 ByteCnt: 0 UnitID: 2 Region: 0 Filter Seq Num: 10 Filter Def: deny any 0000.0000.0088 0000.0000.1111 log HitCnt: 2 ByteCnt: 172 UnitID: 2 Region: 0 Filter Seq Num: 20 Filter Def: permit any any log HitCnt: 4579 ByteCnt: 456434 UnitID: 2 Region: 0 Filter Seq Num: 65001 Filter Def: deny any any HitCnt: 0 ByteCnt: 0
- To clear ACL accounting
statistics for configured ACLs, choose one of the following options:
- For ACLs configured on a specific
interface, enter the
clear access-list accountingcommand and the direction in global configuration mode. - For all ACLs configured in
the device, use the
clear access-list accounting allcommand in global configuration mode.
The following example clears accounting statistics for inbound ACLs on interface 1/1/5.The following example clears accounting statistics for inbound ACLs on LAG 3.The following example clears accounting statistics for inbound ACLs on VLAN 22.The following example clears all ACL accounting statistics. - For ACLs configured on a specific
interface, enter the
The following example enables ACL accounting for a standard IPv4 ACL and applies the ACL to an interface.
device# configure terminal device(config)# ip access-list standard myacl device(config-std-ipacl-myacl)# permit 10.10.10.0/24 device(config-std-ipacl-myacl)# deny 20.20.20.0/24 device(config-std-ipacl-myacl)# enable accounting device(config-std-ipacl-myacl)# interface ethernet 1/1/1 device(config-if-e1000-1/1/1)# ip access-group myacl in
The following example enables accounting for an IPv6 ACL and applies the ACL to an interface.
device# configure terminal device(config)# ipv6 access-list acl_ipv6 device(config-ipv6-access-list acl_ipv6)# enable accounting device(config)# interface ethernet 1/1/1 device(config-if-1/1/1)# ipv6 access-group acl_ipv6 in
The following example enables accounting for a MAC ACL and applies the ACL to a LAG interface.
device# configure terminal device(config)# mac access-list macdata device(config-macl-macdata)# deny any 0000.0000.0088 0000.0000.1111 device(config-macl-macdata)# permit any any device(config-macl-macdata)# enable accounting device(config-macl-macdata)# interface lag 46 device(config-lag-if-lg46)#)# mac access-group macdata in