Other HPE Product Questions
1837960 Members
2482 Online
110124 Solutions
New Discussion

5406r zl2 - ACL Logging not working

 
domwo
Occasional Visitor

5406r zl2 - ACL Logging not working

Hi everyone,

we have a 5406r zl2 as a core switch in use. Besides others, there are 2 VLANs for certain servers (2) and for guests (8).  There's an extended ACL on VLAN 8 with, besides others, the following entry: 

10 deny ip 192.168.8.0 0.0.0.255 192.168.2.0 0.0.0.255 log

show debug returns the following:

Debug Logging

Source IP Selection: Outgoing Interface
Origin identifier: Outgoing Interface IP
Destination:
Logging --
192.168.2.55
Protocol = UDP
Port = 514
Facility = syslog
Severity = info
System Module = all-pass
Priority Desc =

Time-stamp: System-Uptime

Enabled debug types:
acl log

The SysLog server is reachable, we do get some basic syslog entries like "Port XY is now on-/offline" from the 5406r on it but there are not entries for the ACL hits. The Hit Count on the ACE rises when i do some testing but nothing is sent to the syslog server. Did i miss some additional setting?

 

Best regards,

Dom

 

 

1 REPLY 1
Sunitha_Mod
Honored Contributor

Re: 5406r zl2 - ACL Logging not working

Hello @domwo

Thank you for writing to us!  

 HPE Networking forum has moved to Aruba Airheads Community and for HPE networking and Aruba product queries, request you to visit and post your query here: Aruba Airheads Community 

You can refer to the below link as well for more details:

HPE Networking forum migration to Aruba Airheads c... - Hewlett Packard Enterprise Community