Troubleshooting An Acl Rule That Does Not Have A Log Keyword; Troubleshooting A Maximum Flow Limit Value That Is Too Low - Cisco Nexus 1000V Troubleshooting Manual

Hide thumbs Also See for Nexus 1000V:
Table of Contents

Advertisement

Troubleshooting ACL Logging
S e n d d o c u m e n t c o m m e n t s t o n e x u s 1 k - d o c f e e d b a c k @ c i s c o . c o m .

Troubleshooting an ACL Rule That Does Not Have a Log Keyword

If the ACL rule does not have a log keyword, any flow matching the ACL is not reported although the
ACL statistics continue to advance. You can verify a log keyword by entering the commands shown in
the following procedure.
BEFORE YOU BEGIN
Before beginning this procedure, you must know or do the following:
SUMMARY STEPS
1.
2.
3.
PROCEDURE
Command
Step 1
show running-config aclmg
Example
n1000v # show running-config aclmg
n1000v #
Step 2
show logging ip access-list status
Example:
n1000v # show logging ip access-list
status
n1000v #
Step 3
vemcmd show acllog config
Example:
n1000v # vemcmd show acllog config
n1000v #

Troubleshooting a Maximum Flow Limit Value That is Too Low

If the number of flows does not reach 5000 for either permit of deny flows, you can increase the
maximum flows by entering the commands shown in the following procedure.
BEFORE YOU BEGIN
Before beginning this procedure, you must know or do the following:
SUMMARY STEPS
1.
Cisco Nexus 1000V Troubleshooting Guide, Release 4.2(1)SV2(2.1)
15-6
You are logged in to the VSM and VEM CLI.
show running-config aclmgr
show logging ip access-list status
vemcmd show acllog config
You are logged in to the VSM and VEM CLI.
show logging ip access-list status
Description
Verify that the log keyword is enabled
Verify that ACL logging is configured properly
Verifies ACL logging on the VEM.
Chapter 15
ACLs
OL-28795-01

Advertisement

Table of Contents
loading

Table of Contents