ACLs not showing hit counts on active UDP SYSLOG

Apr 02, 2005 7 Replies

I've got an active ACL that is permitting syslog(UDP 514) through to thre syslog servers (gigs worth per day), but the ACLs show no match. I've gone over them repeatedly and there is no match other thatn those we wrote to open syslog up, but no hitcounts. Other lines in the ACl have millions of hits.



Is there some reason why an ACL WON'T show hit counts? Is UDP not tracked with hitcount?



DiGiTAL_ViNYL (no email)


In article , DigitalVinyl wrote: :I've got an active ACL that is permitting syslog(UDP 514) through to :thre syslog servers (gigs worth per day), but the ACLs show no match. :I've gone over them repeatedly and there is no match other thatn those :we wrote to open syslog up, but no hitcounts. Other lines in the ACl :have millions of hits.

:Is there some reason why an ACL WON'T show hit counts? :Is UDP not tracked with hitcount?

Is the syslog being generated -at- the device itself? If so then it would only pass through outgoing ACLs, not incoming ACLs (unless you use a particular 'service' option.) Traffic generated by the device itself does not enter "in" any physical interface.

An experiment: try changing the permit to a deny and see if the syslog still gets through.

Well that would be one way. :-) We actually installed these permits BECAUSE the traffic wasn't going through. Now it is but the ACLs haven't show a hit in weeks.

THe syslogs come from any of ~100 devices located on dozens of networks. They all converge on this one x.x.x.61 VLAN, and the 6509 has the ACL applied on the OUT for the router interface on the VLAN. The 61VLANout ACL shows other hits, such as to the .61 backup server and some other mgmt servers, but the syslog has no hitcount. THere is no other way onto the VLAN, so it should definitely hit this ACL. I was wondering if UDPs don't get counted or some oddity about syslog.

We log gigs per day and most come from beyond the 6509 itself, so I know it is routing a heck of a lot of packets to the syslog servers.

DiGiTAL_ViNYL (no email)

In article , DigitalVinyl wrote: :THe syslogs come from any of ~100 devices located on dozens of :networks. They all converge on this one x.x.x.61 VLAN, and the 6509 :has the ACL applied on the OUT for the router interface on the VLAN. :The 61VLANout ACL shows other hits, such as to the .61 backup server :and some other mgmt servers, but the syslog has no hitcount. THere is :no other way onto the VLAN, so it should definitely hit this ACL. I :was wondering if UDPs don't get counted or some oddity about syslog.

Definitely unusual.

Gigs of logs... ummm, could you fit in a router reboot somewhere along the way?

Yeah, I know. Against mgmt decisions I have already turned down sysloggin from a debugging level to something mroe useful like warning. We were getting up 600mb/hr from a firewall alone. There is a point were too much information becomes the equivalent of ignorance.

This is a ditribution router for the largest access layer block and all of IT services. Rebooting them is akin to asking to reboot the cores (which actually do less work than this ditribution router). They're a redundant pair but I have no confidence in that design. It would have to be a middle of the night thing and this oddity probably isn't worth the trouble. Maybe when we schedule a fix for spanning tree miconfigurations I'll get a reboot in too.

DiGiTAL_ViNYL (no email)

In article , DigitalVinyl wrote: :>Gigs of logs...

:Yeah, I know. Against mgmt decisions I have already turned down :sysloggin from a debugging level to something mroe useful like :warning. We were getting up 600mb/hr from a firewall alone. There is a :point were too much information becomes the equivalent of ignorance.

We pull 73 to 200 Mb a day (at debug level) [more than 1 gig the day one of the major worms started up], and it's Too Much Information :(

If I might ask, what program do you use to analyze/ summarize your logs? I usually find that even with my custom tools that 100 Mb (a day's logs) takes me about 8 hours to analyze and and repair all the broken services. [We block by default so I occasionally have to scan to see what is not getting through but should be.]

Kiwi has some nice filtering, but there isn't time or company desire to stay on top of anything basic nevermind to perform due diligence on the logs.

I'm just struggling to get all the devices actually logging and get pages out for EMERGency level wanings--which everyone has been missing up to now.

This site is too large (12,000 users) for any manual processing of logs except for the investigation of a issue or change.

I think this company is the reverse--everything goes through and we block when the problem is big enough for everyone to notice. (sigh) DiGiTAL_ViNYL (no email)

I found the answer on a Cisco forum. Packets switched in hardware are not counted on the ACL hitcounts, so only exception traffic will be noted. DiGiTAL_ViNYL (no email)

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required