<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Log / mirror ACL's on Egress in ExtremeSwitching (EXOS/Switch Engine)</title>
    <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/log-mirror-acl-s-on-egress/m-p/44553#M10947</link>
    <description>Have created an ACL policy and applied to a vlan on Egress. I know you can log to mirror-cpu on ingress but not egress, but I need away to find out what is causing problems.&lt;BR /&gt;
&lt;BR /&gt;
My ACL is written in the format of permits and an explict deny at the end.&lt;BR /&gt;
&lt;BR /&gt;
In order to stop my ACL killing service I have changed the explict deny at the end to a explict permit, and configured a count.&lt;BR /&gt;
&lt;BR /&gt;
I can see the count racking up, which it shouldn't as I am really only denying on a security beach.&lt;BR /&gt;
&lt;BR /&gt;
Any ideas?&lt;BR /&gt;
&lt;BR /&gt;
Perhaps the only method is to run a packet capture and just workout what traffic I've missed, of course logging the deny's on the rule would be a lot easier by far.&lt;BR /&gt;
&lt;BR /&gt;
Thanks in advance.</description>
    <pubDate>Fri, 21 Aug 2015 15:03:00 GMT</pubDate>
    <dc:creator>Anonymous</dc:creator>
    <dc:date>2015-08-21T15:03:00Z</dc:date>
    <item>
      <title>Log / mirror ACL's on Egress</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/log-mirror-acl-s-on-egress/m-p/44553#M10947</link>
      <description>Have created an ACL policy and applied to a vlan on Egress. I know you can log to mirror-cpu on ingress but not egress, but I need away to find out what is causing problems.&lt;BR /&gt;
&lt;BR /&gt;
My ACL is written in the format of permits and an explict deny at the end.&lt;BR /&gt;
&lt;BR /&gt;
In order to stop my ACL killing service I have changed the explict deny at the end to a explict permit, and configured a count.&lt;BR /&gt;
&lt;BR /&gt;
I can see the count racking up, which it shouldn't as I am really only denying on a security beach.&lt;BR /&gt;
&lt;BR /&gt;
Any ideas?&lt;BR /&gt;
&lt;BR /&gt;
Perhaps the only method is to run a packet capture and just workout what traffic I've missed, of course logging the deny's on the rule would be a lot easier by far.&lt;BR /&gt;
&lt;BR /&gt;
Thanks in advance.</description>
      <pubDate>Fri, 21 Aug 2015 15:03:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/log-mirror-acl-s-on-egress/m-p/44553#M10947</guid>
      <dc:creator>Anonymous</dc:creator>
      <dc:date>2015-08-21T15:03:00Z</dc:date>
    </item>
    <item>
      <title>RE: Log / mirror ACL's on Egress</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/log-mirror-acl-s-on-egress/m-p/44554#M10948</link>
      <description>Well it seems you can! My issue was that I needed the following command:&lt;BR /&gt;
&lt;BR /&gt;
configure log filter DefaultFilter add event kern.card.infoinstead of:&lt;BR /&gt;
&lt;BR /&gt;
configure log filter DefaultFilter add event kern.info&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Mon, 24 Aug 2015 17:40:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/log-mirror-acl-s-on-egress/m-p/44554#M10948</guid>
      <dc:creator>Anonymous</dc:creator>
      <dc:date>2015-08-24T17:40:00Z</dc:date>
    </item>
    <item>
      <title>RE: Log / mirror ACL's on Egress</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/log-mirror-acl-s-on-egress/m-p/44555#M10949</link>
      <description>Sounds like you figured this one out over the weekend.  Thanks for coming back to update the post.&lt;BR /&gt;</description>
      <pubDate>Mon, 24 Aug 2015 17:40:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/log-mirror-acl-s-on-egress/m-p/44555#M10949</guid>
      <dc:creator>Drew_C</dc:creator>
      <dc:date>2015-08-24T17:40:00Z</dc:date>
    </item>
  </channel>
</rss>

