All Packets Are Blocked; Re-Creating Ip-Acls Using Fabric Manager - Cisco 9134 - MDS Multilayer Fabric Switch Troubleshooting Manual

Mds 9000 family
Hide thumbs Also See for 9134 - MDS Multilayer Fabric Switch:
Table of Contents

Advertisement

Chapter 21
Troubleshooting IP Access Lists
S e n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a c k - d o c @ c i s c o . c o m

All Packets Are Blocked

Symptom
Table 21-3
All Packets Are Blocked
Symptom
Possible Cause
All packets are
Access list is empty.
blocked.
A deny filter is too broad.
Deny filter is too high in the access list
order.
No existing permit filters match the
packets.

Re-creating IP-ACLs Using Fabric Manager

To re-create an IP-ACL using Fabric Manager, follow these steps:
Choose Switches > Security > IP ACL and select the Interfaces tab.
Step 1
Right-click all interfaces that have the IP-ACL you need to modify and remove the IP-ACL name from
Step 2
the ProfileName field.
Step 3
Click Apply Changes to save these changes.
Click the IP ACL wizard icon. You see the IP-ACL wizard dialog box.
Step 4
Add the IP-ACL name in the name field and click Add.
Step 5
OL-9285-05
All packets are blocked.
Solution
Remove the access list from the interface. Choose
Switches > Security > IP ACL in Fabric Manager, select
the Interfaces tab, and remove the ACL name from the
ProfileName field. Click Apply Changes.
Or use the no ip access-group or the no ipv6 traffic-filter
CLI command in interface mode.
Delete the deny filter. Choose Security > IP ACL in
Device Manager, right-click the access list, and click
Rules. Right-click the filter you want to delete and click
Delete.
Or use the no ip access-list for IPv4-ACLs or no ipv6
access-list for IPv6, and use the no deny CLI command in
IP-ACL configuration submode.
Delete the access list and re-create. See the
IP-ACLs Using Fabric Manager" section on page 21-5
the
"Re-creating IP-ACLs Using the CLI" section on
page
21-6.
Add an appropriate permit filter. Choose Security > IP
ACL in Device Manager, right-click the access list, and
click Rules. Click Create.
Or use the ip access-list for IPv4-ACLs or ipv6 access-list
for IPv6, and use the permit CLI command in IP-ACL
configuration submode.
Cisco MDS 9000 Family Troubleshooting Guide, Release 3.x
IP-ACL Issues
"Re-creating
or
21-5

Hide quick links:

Advertisement

Table of Contents

Troubleshooting

loading

Table of Contents