Access control list (ACL) contract logs record traffic that contract rules permit or deny in the Cisco Application Centric Infrastructure (ACI) fabric.
ACL contract permit and deny logging provides visibility into traffic flows that are evaluated against contract rules.
-
Permit logs record packets or flows that contract permit rules allow.
-
Deny logs record packets or flows that taboo contract rules, deny actions in contract subjects, or contract and subject exceptions drop.
-
Beginning with Cisco Application Policy Infrastructure Controller (APIC) Release 3.2(1), permit and deny log output can identify the source and destination endpoint groups (EPGs).
Platform support and restrictions
-
ACL contract permit logging is supported on Cisco Nexus 9000 Series switches whose model names end in -EX or -FX, and on later switch models. Supported models include the Cisco Nexus N9K-C93180LC-EX and N9K-C9336C-FX switches.
-
ACL contract deny logging is supported on all platforms.
-
The log directive is not supported on filters in management contracts. Configuring the directive causes zoning-rule deployment to fail.
EPG information in log output
The availability and accuracy of EPG information in permit and deny log output depend on the traffic path and the current fabric configuration.
-
EPG information might be unavailable because of the position of an EPG in the network.
-
EPG information might be temporarily out of date after a configuration change. The information is accurate when the fabric reaches a steady state.
-
EPG information in log output is not supported for microsegmented EPGs or EPGs used by shared services, including shared Layer 3 Outside (L3Out) connections.
Traffic flows with the most accurate EPG information
Permit and deny logs provide the most accurate EPG information for the following traffic flows:
-
EPG-to-EPG flows where the ingress policy is installed on the ingress top-of-rack (ToR) leaf switch and the egress policy is installed on the egress ToR leaf switch.
-
EPG-to-L3Out flows where one policy is applied on the border leaf switch and the other policy is applied on a non-border leaf switch.
Release behavior
Before Cisco APIC Release 3.2(1), ACL permit and deny logs did not identify the EPGs associated with the logged contracts. Beginning with Release 3.2(1), the log output includes the source and destination EPGs when that information is available.
For more information about standard contracts, taboo contracts, and contract subjects, see the Cisco Application Centric Infrastructure Fundamentals and Cisco APIC Basic Configuration Guide .