Cisco Catalyst 9800 Series Wireless Controller Software Configuration Guide, Cisco IOS XE 26.1.x

Cisco Catalyst 9800 Series Wireless Controller Software Configuration Guide, Cisco IOS XE 26.1.x

Access point client ACL counters

Want to summarize with AI?

Log in

Explains the AP Client ACL Counter feature that provides statistical counts for client ACL rules.


An access point client ACL counter is a statistical tracking feature that

  • provides a count for client ACL rules to determine which rule was passing or dropping packets

  • enables counting of packets that hit a specific rule in the client ACL, and

  • is supported in FlexConnect mode and local switching central authentication sub-mode.

AP commands for ACL counter management

Use these AP commands to enable and manage the counter in the AP:

  • [no] debug flexconnect access-list counter [all | vlan-ACL | client-ACL]

  • [no] debug flexconnect access-list event [all | vlan-ACL | client-ACL]

To clear ACL counters use this command:

  • clear counters access-list client <MAC> all

Note

This feature is available from the Cisco IOS XE Dublin 17.13.1 release. Until the Cisco IOS XE Dublin 17.12.1 release, there was no per-rule counter to determine which rule was passing or dropping the packets.


Feature history for Access Point Client ACL Counter

This table provides release and related information about the feature explained in this section.

This feature is also available in all the releases subsequent to the one in which they are introduced in, unless noted otherwise.

Table 1. Feature History for Access Point Client ACL Counter

Release

Feature

Feature Information

Cisco IOS XE Dublin 17.13.1

Access Point Client ACL Counter

The AP Client ACL Counter feature provides a statistical count for client ACL rules. This feature allows you to count the number of packets that hit a specific rule in the client ACL.