Debugging Policy Verification Issues; Troubleshooting Acl Logging - Cisco Nexus 1000V Troubleshooting Manual

Switch for vmware vsphere. release 5.2(1)sv3(1.1)
Hide thumbs Also See for Nexus 1000V:
Table of Contents

Advertisement

Chapter 16
ACLs
AclId RefCnt Type Rules StatId AclName (Stats: Permit/Deny/NoMatch)
----- ------ ---- ----- ------ ------------------------------------
1 0 IPv4 1 1 v4 (Enb: 0/0/0)
2 0 IPv6 0 2 v6 (Dis: 0/0/0)
The Acl-id is the local ACLID for this VEM. Ref-cnt refers to the number of instances of this ACL in
this VEM.
Use the following command to list the interfaces on which ACLs have been installed
~ # module vem 3 execute vemcmd show acl pinst
LTL
16

Debugging Policy Verification Issues

You can debug a policy verification failure.
This section is applicable only to VEMs that are available in older releases. The VEMs in the latest
Note
release do not have any policy verification failure issue.
On the VSM, redirect the output to a file in bootflash.
Step 1
debug logfile filename
Enter the debug aclmgr all command.
Step 2
Enter the debug aclcomp all command.
Step 3
For the VEMs where the policy exists, or is being applied, enter the following these steps from the VSM.
The output goes to the console.
Enter the module vem module-number execute vemdpalog debug sfaclagent all command.
Step 4
Enter the module vem module-number execute vemdpalog debug sfpdlagent all command.
Step 5
Enter the module vem module-number execute vemlog debug sfacl all command.
Step 6
Enter the module vem module-number execute vemlog start command.
Step 7
Enter the module vem module-number execute vemlog start command.
Step 8
Step 9
Configure the policy that was causing the verify error.
Step 10
Enter the module vem module-number execute vemdpalog show all command.
Step 11
Enter module vem module-number execute vemlog show all command.
Save the Telnet or SSH session buffer to a file. Copy the logfile created in bootflash.

Troubleshooting ACL Logging

This section includes the following topics:
OL-31593-01
Acl-id
Dir
1
ingress
Using the CLI to Troubleshoot ACL Logging on a VEM, page 16-4
Cisco Nexus 1000V Troubleshooting Guide, Release 5.2(1)SV3(1.1)
Debugging Policy Verification Issues
16-3

Advertisement

Table of Contents
loading

Table of Contents