Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations gkittelson on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Implicit deny on interface

Status
Not open for further replies.

North323

Technical User
Jan 13, 2009
966
US
all of our network gear is using syslog. we have access lists on most of the outside and inside interfaces. on some we have explicit deny statements like access-list SOMETHING ip deny any any. on other interfaces we do not have this explicit deny but the interface should IMPLICITLY deny traffic. will that IMPLICIT deny traffic be logged to syslog?
 
syslog i believe takes local output and pushes it to a syslog server, ie if your acl had ip deny any any it would silently blocking access, if you wack log on the end of the any any bit it will echo in the console or if telnetted type term mon which will then echo it to you telnet session when the rule is matched.

 
No.

Only deny ip any any log (note the keyword "log", along with the actual "deny any any". Also, sh access-l will show matches only for written lines.

Burt
 
so the implicit deny that does not appear on the 'sh run' will not write to syslog
 
That's correct!!I you want to see the deny follow Burt's suggestion.
Regards
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top