Explains the AP Client ACL Counter feature that provides statistical counts for client ACL rules.
An access point client ACL counter is a statistical tracking feature that
-
provides a count for client ACL rules to determine which rule was passing or dropping packets
-
enables counting of packets that hit a specific rule in the client ACL, and
-
is supported in FlexConnect mode and local switching central authentication sub-mode.
AP commands for ACL counter management
Use these AP commands to enable and manage the counter in the AP:
-
[no] debug flexconnect access-list counter [all | vlan-ACL | client-ACL]
-
[no] debug flexconnect access-list event [all | vlan-ACL | client-ACL]
To clear ACL counters use this command:
-
clear counters access-list client <MAC> all
This feature is available from the Cisco IOS XE Dublin 17.13.1 release. Until the Cisco IOS XE Dublin 17.12.1 release, there was no per-rule counter to determine which rule was passing or dropping the packets.