Showing posts with label ACL. Show all posts
Showing posts with label ACL. Show all posts

Sunday, 2 December 2012

Access List Entry log and log-input

The log and log-input options apply to an individual ACE and cause packets that match the ACE to be logged. The log-input option enables logging of the ingress interface and source MAC address in addition to the packet's source and destination IP addresses and ports.



http://www.cisco.com/web/about/security/intelligence/acl-logging.html#2

Saturday, 1 December 2012

Hash Value Generation for Access Control Entry

ip access-list logging hash-generation

Cisco IOS routers generate syslog entries for log-enabled ACEs. The system appends a tag (either a user-defined cookie or a router-generated MD5 hash value) to ACE syslog entries. This tag uniquely identifies the ACE, within an access control list (ACL), that generated the syslog entry.


http://www.cisco.com/en/US/docs/ios/security/command/reference/sec_i1.html#wp1042763