logging enable (ACL)

Enables logging for an IPv4, IPv6, or MAC ACL.
Syntax
logging enable
no logging enable
Command Default

ACL logging is not enabled.

Modes

ACL filter configuration sub-mode

or

ACL binding configuration sub-mode

Usage Guidelines

The no form of the command disables ACL logging.

The logging enable command is used in conjunction with the keyword log, configured as part of an ACL filter statement, to determine which traffic and actions are logged.

From FastIron release 08.0.95, the logging enable command, applied at the ACL binding level, replaces the logging-enable command, which was applicable only at the interface configuration or ACL filter configuration level.

Examples

The following example enables logging for an IPV6, MAC, and IPv4 ACL in VLAN 222. The show ip access-lists 136 command confirms that logging occurs in IPv4 extended ACL 136 when traffic from a particular set of IP addresses is denied. The statements in the other ACLs can be checked for the log option in the same way. The show running-config vlan 222 command confirms VLAN configuration.

device# show ip access-lists 136
Extended IP access list 136: 1002 entries
enable accounting
8: deny ip 99.99.99.0 0.0.0.255 any log <-- IPv4 extended deny statement includes log action

device# configure terminal
device(config)# vlan 222 by port
device(config-vlan-222)# vlan 222 by port
device(config-vlan-222)# tagged ethe 2/1/12 lag 45
device(config-vlan-222)# interface ve 222
device(config-vlan-222)# ipv6 access-group ipv6acl in logging enable
device(config-vlan-222)# mac access-group mac in logging enable
device(config-vlan-222)# ip access-group 136 in logging enable <-- IPv4 ACL 136 w/ logging enabled
!
!
device(config-vlan-222)# show running-config vlan 222
vlan 222 by port
tagged ethe 2/1/12 lag 45
router-interface ve 222
ipv6 access-group ipv6acl in logging enable
mac access-group mac in logging enable
ip access-group 136 in logging enable
!
!
device(config-vlan-222)# exit
device(config)#

The following examples check the contents of the MAC and IPv6 ACLs used in the previous example and confirm that statements containing the log option will trigger a log entry when matched.

device# show mac access-lists mac
mac access-list mac
deny any 0000.0000.0088 0000.0000.1111 log
permit any any log

device(config-ipv6-access-list ipv6acl)# show ipv6 access-lists ipv6acl
ipv6 access-list ipv6acl: 1 entry
10: permit ipv6 any any log
History
Release version Command history
08.0.95 This command was introduced to replace the logging-enable command.