logging enable (ACL)
ACL logging is not enabled.
ACL filter configuration sub-mode
or
ACL binding configuration sub-mode
The
no form of the command disables ACL logging.
The
logging enable command is used in conjunction with the keyword
log, configured as part of an ACL filter statement, to determine which traffic and actions
are logged.
From FastIron release 08.0.95, the
logging enable command, applied at the ACL binding level, replaces the
logging-enable command, which was applicable only at the interface configuration or ACL filter configuration
level.
The following example enables logging for an IPV6, MAC, and IPv4 ACL in VLAN 222.
The
show ip access-lists 136 command confirms that logging occurs in IPv4 extended ACL 136 when traffic from a
particular set of IP addresses is denied. The statements in the other ACLs can be
checked for the
log option in the same way. The
show running-config vlan 222
command confirms VLAN configuration.
device# show ip access-lists 136 Extended IP access list 136: 1002 entries enable accounting 8: deny ip 99.99.99.0 0.0.0.255 any log <-- IPv4 extended deny statement includes log action device# configure terminal device(config)# vlan 222 by port device(config-vlan-222)# vlan 222 by port device(config-vlan-222)# tagged ethe 2/1/12 lag 45 device(config-vlan-222)# interface ve 222 device(config-vlan-222)# ipv6 access-group ipv6acl in logging enable device(config-vlan-222)# mac access-group mac in logging enable device(config-vlan-222)# ip access-group 136 in logging enable <-- IPv4 ACL 136 w/ logging enabled ! ! device(config-vlan-222)# show running-config vlan 222 vlan 222 by port tagged ethe 2/1/12 lag 45 router-interface ve 222 ipv6 access-group ipv6acl in logging enable mac access-group mac in logging enable ip access-group 136 in logging enable ! ! device(config-vlan-222)# exit device(config)#
The following examples check the contents of the MAC and IPv6 ACLs used in the previous example and confirm that statements containing the log option will trigger a log entry when matched.
device# show mac access-lists mac mac access-list mac deny any 0000.0000.0088 0000.0000.1111 log permit any any log device(config-ipv6-access-list ipv6acl)# show ipv6 access-lists ipv6acl ipv6 access-list ipv6acl: 1 entry 10: permit ipv6 any any log