Re: debugging access list

From: jaime.salazar@xxxxxxxxxx
Date: Fri Jan 14 2000 - 01:04:50 GMT-3


   

try using

#debug ip packets <access-list-number>

Jaime

Earl Aboytes <earl@linkline.com> on 13/01/2000 09:40:54 PM

Please respond to Earl Aboytes <earl@linkline.com>

To: "Stein, Jared" <jstein@techdata.com>, "'ccielab@groupstudy.com'"
      <ccielab@groupstudy.com>
cc: (bcc: Jaime Salazar/Mexico/AMERICAS/Equant)

Subject: Re: debugging access list

Use the log statement at the end of the access list and you will get a
count of packets that are hitting the list. I am not sure if you can get
any more specific with it.
Earl

At 08:59 PM 1/13/00 -0500, Stein, Jared wrote:
>Is there anyway to find out what is trying to get through you access list
>applied on an interface.
>
>Example
>
>access list 101 permit icmp any any
>
>can I see what traffic is failing by port? how could I see if gre was
>failing, ftp etc.
>
>Thanks



This archive was generated by hypermail 2.1.4 : Thu Jun 13 2002 - 08:22:44 GMT-3