Access Control Lists (ACLs) for the Series 3400cl and Series 6400cl Switches
Enable ACL “Deny” Logging
For example, suppose that you want to do the following:
■ On port 10, configure an extended ACL with an ACL-ID of 143 to deny
Telnet traffic from IP address 10.38.100.127.
■ Configure the switch to send an ACL log message to the console and
to a Syslog server at IP address 10.38.110.54 on port 11 if the switch
detects a match denying Telnet access from 10.38.100.127.
10.38.110.54
10.38.100.127
Syslog Server
Configure extended ACL 143
here to deny Telnet access to
inbound Telnet traffic from IP
address 10.38.100.127.
Block Telnet access to the
network from this host.
3400cl or 6400cl
Switch
Console
Console RS-232 Port
10
11
Figure 10-33. Example of an ACL Log Application
10-73