
16-5
Cisco Nexus 1000V Troubleshooting Guide, Release 5.2(1)SV3(1.1)
OL-31593-01
Chapter 16 ACLs
Troubleshooting ACL Logging
Showing Flow Debug Statistics
You can show ACL debug statistics.
To display internal ACL flow statistics, enter the following command:
vemcmd show aclflows dbgstats
To clear all internal ACL flow debug statistics, enter the following command:
vemcmd clear aclflows dbgstats
ACL Logging Troubleshooting Scenarios
This section describes situations that you might encounter when you are using ACL logging.
Troubleshooting a Syslog Server Configuration
If syslog messages are not being sent from the VEM, you can check the syslog server configuration and
check if ACL logging is configured by entering the commands shown in the following procedure.
BEFORE YOU BEGIN
•
Log in to the VSM and VEM CLI.
PROCEDURE
Troubleshooting an ACL Rule That Does Not Have a Log Keyword
If the ACL rule does not have a
log
keyword, any flow that matches the ACL is not reported although
the ACL statistics continue to advance. You can verify a
log
keyword.
Command
Description
Step 1
show logging ip access-list status
Example:
switch# show logging ip
access-list status
switch #
Verifies that the remote syslog server is configured
properly.
Step 2
vemcmd show acllog config
Example:
switch# vemcmd show acllog config
switch #
Verifies ACL logging on the VEM.
Step 3
vemcmd show aclflows dbgstats
Example:
switch# vemcmd show aclflows
dbgstats
switch #
Checks to see if any errors occurred.