Using The Cli To Troubleshoot Acl Logging On A Vem; Viewing Current Flows; Viewing Active Flows; Flushing All Acl Flows - Cisco Nexus 1000V Troubleshooting Manual

Hide thumbs Also See for Nexus 1000V:
Table of Contents

Advertisement

Troubleshooting ACL Logging
S e n d d o c u m e n t c o m m e n t s t o n e x u s 1 k - d o c f e e d b a c k @ c i s c o . c o m .

Using the CLI to Troubleshoot ACL Logging on a VEM

The commands in this section will help you troubleshoot ACL logging by examining ACL flows.

Viewing Current Flows

You can troubleshoot ACL logging by viewing the current flows on a VEM. Enter the following
command:
vemcmd show aclflows stats
EXAMPLE
The following shows an example of the output when you enter this command:
[root@esx /]# vemcmd show aclflows stats
Current Flow stats:

Viewing Active Flows

You can display all the active flows on a VEM by entering the following command:
vemcmd show aclflows [permit | deny]
If you do not specify permit or deny, the command displays both.
EXAMPLE
The following shows an example of the output when you enter this command:
[root@esx /]# vemcmd show aclflows [permit | deny]
If
Veth4
Veth4
Veth4
Veth4
Veth4
Veth4
Veth4
Veth4
Veth4
Veth4
Veth4
Veth4
Veth4

Flushing All ACL Flows

You can use this command to detect any new flows affecting the VEM. Clear all the existing flows, then
you can detect new flows that match any expected traffic. Syslog messages are not sent when you do this.
Enter the following command:
vemcmd flush aclflows
Cisco Nexus 1000V Troubleshooting Guide, Release 4.2(1)SV2(2.1)
15-4
Permit Flows:
1647
Deny Flows:
Current New Flows:
419
SrcIP
DstIP
192.168.1.20
192.168.1.10
192.168.1.10
192.168.1.20
192.168.1.20
192.168.1.10
192.168.1.10
192.168.1.20
192.168.1.20
192.168.1.10
192.168.1.10
192.168.1.20
192.168.1.10
192.168.1.20
192.168.1.10
192.168.1.20
192.168.1.20
192.168.1.10
192.168.1.10
192.168.1.20
192.168.1.10
192.168.1.20
192.168.1.20
192.168.1.10
192.168.1.20
192.168.1.10
0
--- current new flows yet to be reported.
SrcPort DstPort Proto Direction Action
5345
8080
6256
8080
5217
8080
8080
8080
5601
8080
8080
5473
57211
8080
6 Ingress
permit
5769
6 Egress
permit
8080
6 Ingress
permit
5801
6 Egress
permit
8080
6 Ingress
permit
57211
6 Egress
permit
5865
6 Egress
permit
5833
6 Egress
permit
8080
6 Ingress
permit
5705
6 Egress
permit
5737
6 Egress
permit
8080
6 Ingress
permit
8080
6 Ingress
permit
Chapter 15
ACLs
Stats
1
1
1
1
1
1
1
1
1
1
1
1
1
OL-28795-01

Advertisement

Table of Contents
loading

Table of Contents