
Monitoring ACLs
294 Enterasys Xpedition User Reference Manual
Before enabling ACL logging, you should consider its impact on performance. With ACL
logging enabled, the router prints out a message at the console before the packet is
actually forwarded or dropped. Even if the console is connected to the router at a high
baud rate, the delay caused by the console message is still significant. This can get worse if
the console is connected at a low baud rate, for example, 1200 baud. Furthermore, if a
Syslog server is configured, then a Syslog packet must also be sent to the Syslog server,
creating additional delay. Therefore, you should consider the potential performance
impact before turning on ACL logging.
Monitoring ACLs
The XP provides a display of ACL configurations active in the system.
To display ACL information, enter the following commands in Enable mode.
Show all ACLs.
acl show all
Show a specific ACL. acl show aclname <name> | all
Show an ACL on a specific interface. acl show interface <name>
Show ACLs on all IP interfaces.
acl show interface all-ip
Show static entry filters.
acl show service
Commentaires sur ces manuels