Displays access control list (ACL) logs for permitted and denied network traffic.
Before you begin
Enable ACL permit or deny logging and generate traffic that matches the logged rule.
Procedure
-
On the menu bar, choose Tenants > tenant_name .
-
In the Navigation pane, click the tenant_name root node.
-
In the Work pane, click the Operational tab.
-
Click the Flows tab.
-
To view the required log data, click L2 Permit , L3 Permit , L2 Drop , or L3 Drop .
The available data depends on the log type and ACL rule. Layer 3 permit and drop logs can include the following fields:
VRF
Alias
Source IP address
Destination IP address
Protocol
Source port
Destination port
Source MAC address
Destination MAC address
Node
Source interface
VRF encapsulation
Source EPG
Destination EPG
Source PC tag
Destination PC tag
-
Click the Packets tab to view ACL logs for groups of packets that have the same signature, source, and destination.
Each group can contain up to 10 packets. The logs identify the packet types and indicate which packets were dropped.