Solved

Acl matches not showing

Posted on 2003-12-02
7
366 Views
Last Modified: 2010-04-17
Hi all
My question is about ACL

here is my acl

permit tcp any host 172.16.88.20 eq smtp log
deny   tcp any host 172.16.88.253 eq ftp log
deny   tcp any host 172.16.88.253 eq 22 log
deny   tcp any host172.16.88.253  eq telnet log
deny   tcp any host 172.16.88.253  eq sunrpc log
deny   tcp any host 172.16.88.253  eq ftp-data log
deny   icmp any host 202.163.80.253 log

Now my question is when i give the command
show access-list

it dows not show  the matches

permit tcp any host 172.16.88.20 eq smtp log (10 matches)
( as this is our mail server and we are recieving mails succesfully)

how can i enable my router that it show the matches when i issue command

Waiting for early response
0
Comment
Question by:iam23m
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
7 Comments
 
LVL 7

Expert Comment

by:NicBrey
ID: 9858679
Hi there
You have to enable logging on the router, either to a syslog server or to memory

To log to a memory buffer:
router(config)# logging buffered <level of logging you require>     <----  use the  " ? "  key to see the options

To log to syslog server:
router(config)# logging <ip address of syslog server>

View the memory buffer log:
router#  show log


0
 
LVL 7

Expert Comment

by:NicBrey
ID: 9858741
I suggest that you log to a external syslog server save router resources.

Link to syslog daemon for Windows:
http://www.kiwisyslog.com/

But it you are going to log to memory, use the "clear log" command to clean out the log.
0
 
LVL 3

Accepted Solution

by:
MaxQ earned 125 total points
ID: 9861297
I don't think it's a question about logging messages as much as the hit counters for each line of the access list.  

My first guess would be that "ip route-cache" is turned on, which means that the router will fast-switch all of the packets after the first one in each flow, so only that first packet will show up in the ACL counters.  

If your router isn't extremely busy you can turn off the feature (I wouldn't recommend leaving it this way though) with "no ip route-cache" on the interfaces in question if you need to see the exact numbers of hits on each line in the ACL.
0
 
LVL 12

Assisted Solution

by:Scotty_cisco
Scotty_cisco earned 125 total points
ID: 9869532
I think MaxQ is on the right path but I got the impression that he was not showing any matches? Is this correct?  If this is the case I would try adding the log statment to the end of the ACL for some testing and check to see if the packets are actually hitting the ACL.  If they are, I have seen some situations where different versions of IOS shows the packet counts and others do not.  For instance route-maps are that way in many of the 12.1 versions they are not shown as hitting the ACL when we upgraded to 12.2 they started showing.  Also check the direction of the applied access list I know it sounds dumb but that has bitten me more than once ....

Thanks
Scott
0

Featured Post

Space-Age Communications Transitions to DevOps

ViaSat, a global provider of satellite and wireless communications, securely connects businesses, governments, and organizations to the Internet. Learn how ViaSat’s Network Solutions Engineer, drove the transition from a traditional network support to a DevOps-centric model.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In the hope of saving someone else's sanity... About a year ago we bought a Cisco 1921 router with two ADSL/VDSL EHWIC cards to load balance local network traffic over the two broadband lines we have, but we couldn't get the routing to work consi…
How to set-up an On Demand, IPSec, Site to SIte, VPN from a Draytek Vigor Router to a Cyberoam UTM Appliance. A concise guide to the settings required on both devices
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

751 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question