Enables access control list (ACL) logging for packets and flows that a taboo contract denies.
Apply the log directive to a taboo contract filter to record matching denied traffic.
Procedure
-
On the menu bar, choose Tenants > tenant_name .
-
In the Navigation pane, expand Contracts .
-
Right-click Taboos and choose Create Taboo Contract .
-
In the Create Taboo Contract dialog box, configure the taboo contract.
- In the Name field, enter a name for the taboo contract.
- Optional: In the Description field, enter a description.
- Next to Subjects , click + .
-
In the Create Taboo Contract Subject dialog box, configure the subject and select a filter.
- In the Specify Identity of Subject area, enter a name for the subject.
- Optional: Enter a description of the subject.
- Next to Filters , click + .
- From the Name drop-down list, choose an existing filter, choose a default filter, or choose Create Filter .
The default filters include tenant_name /arp , tenant_name /default , tenant_name /est , and tenant_name /icmp .
-
If you chose Create Filter , configure the filter.
- In the Specify Filter Identity area, enter a name and, optionally, a description.
- Expand Entries , enter a name for the entry, and configure the criteria that identify the traffic to deny.
- Click Update .
- Click OK to create the filter and return to the Create Taboo Contract Subject dialog box.
-
For the selected filter, choose log from the Directives drop-down list, and click Update .
-
In the Create Taboo Contract Subject dialog box, click OK .
-
In the Create Taboo Contract dialog box, click Submit .
Deny logging is enabled for traffic that matches the taboo contract filter.