Configuring ACL Accounting

If you enable accounting for an ACL, it applies to all rules in that ACL, including implicit rules.
ACL accounting is disabled by default. It is supported and can be enabled on IPv4, IPv6, and MAC ACLs.
  1. To enable ACL accounting for a configured ACL, use the enable accounting command in IPv4, IPv6, or MAC ACL configuration sub-mode.
    The following example enables accounting for an IPv4 ACL.
    device(config)# ip access-list standard acl10
    device(config-std-ipacl-acl10)# enable accounting
    The following example enables accounting for an IPv6 ACL.
    device(config)# ipv6 access-list acl_1pv6
    device(config-ipv6-access-list acl_ipv6)# enable accounting 
    
    The following example enables accounting for a MAC ACL.
    device# configure terminal
    device(config)# mac access-list mac123
    device(config-macl-mac123)# enable accounting
    
  2. Display the ACL accounting information using the show access-list accounting command.
    The accounting statistics are collected every five seconds and synchronized to remote units every one minute.
    The following example displays a brief accounting summary for ACLs applied inbound to VLAN 333.
    device# show access-list accounting vlan 333 in brief
    ACL Accounting Table
    ==========================================================================================================================================================
    UnitID: 1 ACL Name: acl_l2            HitCnt: 0   ByteCnt: 0
    UnitID: 1 ACL Name: acl_ipv4          HitCnt: 0   ByteCnt: 0
    UnitID: 1 ACL Name: acl_ipv6          HitCnt: 0   ByteCnt: 0
    UnitID: 2 ACL Name: acl_l2            HitCnt: 0   ByteCnt: 0
    UnitID: 2 ACL Name: acl_ipv4          HitCnt: 0   ByteCnt: 0
    UnitID: 2 ACL Name: acl_ipv6          HitCnt: 0   ByteCnt: 0
    UnitID: 3 ACL Name: acl_l2            HitCnt: 0   ByteCnt: 0
    UnitID: 3 ACL Name: acl_ipv4          HitCnt: 0   ByteCnt: 0
    UnitID: 3 ACL Name: acl_ipv6          HitCnt: 0   ByteCnt: 0
    
    The following example displays an accounting summary for inbound IPv4 ACLs active on VLAN 333.
    device# show access-list accounting vlan 333 in ipv4 brief
    ACL Accounting Table
    ==========================================================================================================================================================
    UnitID: 1 ACL Name: mirror_acl_ipv4     HitCnt: 0     ByteCnt: 0
    UnitID: 2 ACL Name: mirror_acl_ipv4     HitCnt: 0     ByteCnt: 0
    UnitID: 3 ACL Name: mirror_acl_ipv4     HitCnt: 0     ByteCnt: 0
    
    The following example displays summary inbound MAC ACL accounting statistics for VLAN 224.
    device# show access-list accounting vlan 224 in  mac brief
    ACL Accounting Table
    =====================================================================================================
    UnitID: 1      ACL Name: mirror_acl_l2        HitCnt: 0          ByteCnt: 0   
    UnitID: 1      ACL Name: mac                  HitCnt: 1450       ByteCnt: 147144   
    UnitID: 2      ACL Name: mirror_acl_l2        HitCnt: 0          ByteCnt: 0        
    UnitID: 2      ACL Name: mac                  HitCnt: 4581       ByteCnt: 456606   
    UnitID: 4      ACL Name: mirror_acl_l2        HitCnt: 0          ByteCnt: 0        
    UnitID: 4      ACL Name: mac                  HitCnt: 0          ByteCnt: 0        
    
    The following example displays detailed inbound MAC ACL accounting statistics for VLAN 224.
    device# show access-list accounting vlan 224 in  mac detail
    ACL Accounting Table
    ================================================================================================
    ACL Name: mac
    UnitID: 1  Region: 0  Filter Seq Num: 10     Filter Def: deny any 0000.0000.0088 0000.0000.1111 log  
       HitCnt: 9    ByteCnt: 774
    UnitID: 1  Region: 0  Filter Seq Num: 20     Filter Def: permit any any log                          
       HitCnt: 1441 ByteCnt: 146370
    UnitID: 1  Region: 0  Filter Seq Num: 65001  Filter Def: deny any any                                
       HitCnt: 0    ByteCnt: 0
    UnitID: 2  Region: 0  Filter Seq Num: 10     Filter Def: deny any 0000.0000.0088 0000.0000.1111 log  
       HitCnt: 2    ByteCnt: 172
    UnitID: 2  Region: 0  Filter Seq Num: 20     Filter Def: permit any any log                          
       HitCnt: 4579 ByteCnt: 456434
    UnitID: 2  Region: 0  Filter Seq Num: 65001  Filter Def: deny any any
       HitCnt: 0    ByteCnt: 0
    
  3. To clear ACL accounting statistics for configured ACLs, choose one of the following options:
    • For ACLs configured on a specific interface, enter the clear access-list accounting command and the direction in global configuration mode.
    • For all ACLs configured in the device, use the clear access-list accounting all command in global configuration mode.
    The following example clears accounting statistics for inbound ACLs on interface 1/1/5.
    device(config)# clear access-list accounting ethernet 1/1/5 in
    The following example clears accounting statistics for inbound ACLs on LAG 3.
    device(config)# clear access-list accounting lag 3 in
    The following example clears accounting statistics for inbound ACLs on VLAN 22.
    device(config)# clear access-list accounting vlan 22 in
    The following example clears all ACL accounting statistics.
    device(config)# clear access-list accounting all

The following example enables ACL accounting for a standard IPv4 ACL and applies the ACL to an interface.

device# configure terminal
device(config)# ip access-list standard myacl
device(config-std-ipacl-myacl)# permit 10.10.10.0/24
device(config-std-ipacl-myacl)# deny 20.20.20.0/24
device(config-std-ipacl-myacl)# enable accounting
device(config-std-ipacl-myacl)# interface ethernet 1/1/1
device(config-if-e1000-1/1/1)# ip access-group myacl in

The following example enables accounting for an IPv6 ACL and applies the ACL to an interface.

device# configure terminal
device(config)# ipv6 access-list acl_ipv6
device(config-ipv6-access-list acl_ipv6)# enable accounting
device(config)# interface ethernet 1/1/1
device(config-if-1/1/1)# ipv6 access-group acl_ipv6 in

The following example enables accounting for a MAC ACL and applies the ACL to a LAG interface.

device# configure terminal
device(config)# mac access-list macdata
device(config-macl-macdata)# deny any 0000.0000.0088 0000.0000.1111
device(config-macl-macdata)# permit any any
device(config-macl-macdata)# enable accounting
device(config-macl-macdata)# interface lag 46
device(config-lag-if-lg46)#)# mac access-group macdata in