Send documentation comments to mdsfeedback-doc@cisco.com
21-8
Cisco MDS 9000 Family Troubleshooting Guide, Release 3.x
OL-9285-05
Chapter 21 Troubleshooting IP Access Lists
IP-ACL Issues
PortChannel Not Working with ACL
Symptom PortChannel not working with ACL.
Cannot Remotely Connect to Switch
Symptom Cannot remotely connect to switch.
Table 21-5 PortChannel Not Working with ACL
Symptom Possible Cause Solution
PortChannel not
working with ACL
ACL not applied to all interfaces in the
PortChannel.
Add the ACL to all interfaces in the PortChannel. Choose
Switches > ISLs > Port Channels to view the Members
Admin field to find out which interfaces are part of the
PortChannel. Choose Switches > Security > IP ACL on
Fabric Manager, select the Interfaces tab, and add the ACL
name to the ProfileName field. Click Apply Changes.
Or use the show port-channel database CLI command to
find out which interfaces are part of the PortChannel and
then use the ip access-group or the ipv6 traffic-filter CLI
command in interface mode to add the ACL to all interfaces
in the PortChannel.
Table 21-6 Cannot Remotely Connect to Switch
Symptom Possible Cause Solution
Cannot remotely
connect to switch.
Incorrect ACL on mgmt0 interface. Connect to console port locally and delete the ACL. Use
the no ip access-group or the no ipv6 traffic-filter CLI
command in interface mode.