This topic describes how interface logging on IPv4 and IPv6 access control lists (ACLs) generates log messages that identify the interface through which traffic enters or exits the router.
You can enable interface logging on IPv4 and IPv6 access control lists (ACLs) so that log messages identify the interface through which traffic enters or exits the router. The router supports two types of interface logging on ACLs:
-
Ingress interface logging: uses the log-input keyword on ACEs to include, in the log message, the ingress interface on which the router receives the packet. The router supports this feature for both IPv4 and IPv6 ingress ACLs on main interfaces, sub-interfaces, and bridge-group virtual interfaces (BVI).
-
Egress interface logging: uses the log option on ACEs to identify the packet counts matching the ACEs. With this log option, for egress traffic, you can fetch information such as access list number, packets permitted or denied, and source or destination addresses of the packets.
|
Feature Name |
Release Information |
Feature Description |
|---|---|---|
|
ACL Log Message Collection for Egress Traffic |
Release 26.2.1 |
Introduced in this release on: Modular Systems (8800 [LC ASIC: P100]):* *This feature is supported on:
|
|
ACL Log Message Collection for Egress Traffic |
Release 25.4.1 |
Introduced in this release on: Fixed Systems (8010 [ASIC: A100])(select variants only*) *This feature is supported on:
|
|
ACL Log Message Collection for Egress Traffic |
Release 25.1.1 |
Introduced in this release on: Fixed Systems (8700 [ASIC: K100], 8010 [ASIC: A100])(select variants only*) *This feature is supported on:
|
|
ACL Log Message Collection for Egress Traffic |
Release 24.4.1 |
Introduced in this release on: Fixed Systems (8200 [ASIC: P100], 8700 [ASIC: P100])(select variants only*); Modular Systems (8800 [LC ASIC: P100])(select variants only*) *This feature is supported on:
|
|
ACL Log Message Collection for Egress Traffic |
Release 7.10.1 |
We have made it easier for you to monitor ACL egress traffic, assess traffic load on an ACL, and troubleshoot issues. This is made possible by adding a log option to the ACEs that are associated with an interface and identify the packet counts matching the ACEs. With this log option, for an egress traffic, you can fetch information, such as access list number, packets permitted or denied, and source or destination addresses of the packets. |
|
Enable Ingress Interface Logging on IPv4 and IPv6 ACLs |
Release 25.4.1 |
Introduced in this release on: Fixed Systems (8010 [ASIC: A100])(select variants only*) *This feature is supported on:
|
|
Enable Ingress Interface Logging on IPv4 and IPv6 ACLs |
Release 25.1.1 |
Introduced in this release on: Fixed Systems (8700 [ASIC: K100], 8010 [ASIC: A100])(select variants only*) This feature is supported on:
|
|
Enable Ingress Interface Logging on IPv4 and IPv6 ACLs |
Release 24.4.1 |
Introduced in this release on: Fixed Systems (8200 [ASIC: P100], 8700 [ASIC: P100])(select variants only*); Modular Systems (8800 [LC ASIC: P100])(select variants only*) *This feature is supported on:
|
|
Enable Ingress Interface Logging on IPv4 and IPv6 ACLs |
Release 7.8.1 |
Using the log-input keyword, you can now enable Access Control Lists (ACLs) to generate log messages that help you identify the interface through which a particular traffic stream ingresses the routers. This information aids in optimizing traffic flow across the network. There was no option to enable logging of ingress interfaces with an ACL in earlier releases. This feature introduces an optional keyword log-input for the following commands: |