Managing Deny Flows - Cisco Catalyst 6500 Series Configuration Manual

Catalyst 6500 series switch and cisco 7600 series router firewall services
Hide thumbs Also See for Catalyst 6500 Series:
Table of Contents

Advertisement

Logging Extended Access Control List Activity
%FWSM-2-106100: access-list outside-acl denied ip outside/3.3.3.3(12345) ->
inside/192.168.1.1(1357) hit-cnt 1 (first hit)
20 additional attempts within a 5 minute interval (the default) result in the following message at the end
of 5 minutes:
%FWSM-2-106100: access-list outside-acl denied ip outside/3.3.3.3(12345) ->
inside/192.168.1.1(1357) hit-cnt 21 (300-second interval)

Managing Deny Flows

When you enable logging for message 106100, if a packet matches an ACE, the FWSM creates a
flow entry to track the number of packets received within a specific interval. The FWSM has a maximum
of 32K logging flows for ACEs. A large number of flows can exist concurrently at any point of time. To
prevent unlimited consumption of memory and CPU resources, the FWSM places a limit on the number
of concurrent deny flows; the limit is placed only on deny flows (and not permit flows) because they can
indicate an attack. When the limit is reached, the FWSM does not create a new deny flow for logging
until the existing flows expire.
For example, if someone initiates a denial of service (DoS) attack, the FWSM can create a large number
of deny flows in a short period of time. Restricting the number of deny flows prevents unlimited
consumption of memory and CPU resources.
When you reach the maximum number of deny flows, the FWSM issues system message 106100:
%FWSM-1-106101: The number of ACL log deny-flows has reached limit (numbe r).
To configure the maximum number of deny flows and to set the interval between deny flow alert
messages (106101), enter the following commands:
Catalyst 6500 Series Switch and Cisco 7600 Series Router Firewall Services Module Configuration Guide
10-28
To set the maximum number of deny flows permitted per context before the FWSM stops logging,
enter the following command:
FWSM/contexta(config)# access-list deny-flow-max number
The number is between 1 and 4096. 4096 is the default.
To set the amount of time between system messages (number 106101) that identify that the
maximum number of deny flows was reached, enter the following command:
FWSM/contexta(config)# access-list alert-interval secs
The seconds are between 1 and 3600. 300 is the default.
Chapter 10
Controlling Network Access with Access Control Lists
OL-6392-01

Advertisement

Table of Contents
loading

This manual is also suitable for:

7600 series

Table of Contents