Cisco WS-X6066-SLB-APC - Content Switching Module Software Manual page 337

Catalyst 6000 series software configuration guide
Hide thumbs Also See for WS-X6066-SLB-APC - Content Switching Module:
Table of Contents

Advertisement

Chapter 16
Configuring Access Control
To enable VACL logging, perform these steps:
Enter the set logging level acl severity command to set the logging level to 6 (information) or
Step 1
7 (debugging).
(Optional) Enter the set security acl log maxflow max_number to allocate a new log table based on
Step 2
the maximum flow pattern number to store logged packet information. If successful, the new buffer
replaces the old one and all flows in the old table are cleared. If either memory is not enough or the
maximum number is over the limit, an error message is displayed and the command is dropped.
Valid values are from 256 to 2048; the default value is 500.
Note
(Optional) Enter the set security acl log ratelimit pps to set the redirect rate in pps (packet per second).
Step 3
If the configuration is over the range, the command is discarded and the range is displayed on the
console. Valid values are from 500 to 5000; the default value is 2500.
Note
Enter the set security acl ip acl_name deny log command to create an IP VACL and enable logging.
Step 4
Enter the commit security acl acl_name command to commit the VACL to NVRAM.
Step 5
Enter the set security acl map acl_name vlan command to map the VACL to a VLAN.
Step 6
Configuration Examples
This example shows how to set the logging level:
Console> (enable) set logging level acl 6
System logging facility <acl> for this session set to severity 6(information)
This example shows how to allocate a new log table based on the maximum flow:
Console> (enable) set security acl log maxflow 512
Set VACL Log table to 512 flow patterns.
This example shows how to set the redirect rate:
Console> (enable) set security acl log ratelimit 1000
Set Redirect Rate to 1000 pps.
This example shows how to display the VACL log configuration:
Console> (enable) show security acl log config
VACL LOG Configration
-------------------------------------------------------------
Max Flow Pattern
Redirect Rate (pps) : 1000
78-13315-02
If the maximum flow pattern is over the max_num limit, an error message is displayed and
the command is dropped. Messages are not logged for these packets.
If the redirect rate is over the pps range, the command is dropped and the range is displayed
on the console. Messages are not logged for these packets.
: 512
Catalyst 6000 Family Software Configuration Guide—Releases 6.3 and 6.4
Configuring VACLs
16-41

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents