Re: [nsp] removing access-list

From: Josh Duffek (jduffek@cisco.com)
Date: Tue Mar 12 2002 - 15:43:32 EST


Blame me, I filed the bug...someone elses idea though :)

I'm not sure that you can do a "debug ip pack foo" for a named acl, but you
can do it for numbered ones. Let's say you had a numbered acl configured,
say 150, and you had "debug ip pack 150" turned on...now if you removed acl
150 but forgot to turn the debug off you would be debugging all ip packed
which would kill your cpu...

CSCds19448 When removing access-list corresponding debugs should be turned
off
Integrated:12.1(04)DC01 12.1(04.04)EC 012.001(004.002) 12.1(04.02)T
12.1(04.02)AA 12.1(04.03)PI
Release-note:
 The following debugs will be turned off on deleting an acl
 if they are being throttled by that acl:

 1. debug ip packet <acl>
 2. debug ip mpacket <acl>
 3. debug ip error <acl>

Josh

----- Original Message -----
From: "Birsen Ozturk" <birsen.ozturk@is.net.tr>
To: <cisco-nsp@puck.nether.net>
Sent: Tuesday, March 12, 2002 6:35 AM
Subject: [nsp] removing access-list

Hello Everybody
On my Cisco 7204 I am using IOS version 12.2(1). When all debugging is
disabled on the router, I removed an unused standard access-list:

cisco7204(config)#no ip access-list standard BLAH-BLAH
IP NAT debugging is off
IP packet debugging is off
Turning off all possible debuugging on ACL 0
cisco7204(config)#end
cisco7204#

Why it's saying that debugging is turned off when it is already off? What is
ACL 0? I don't have such an access list configured? It does not affect the
operation, I am just curious:)

Birsen Ozturk
ISNET@AS9021
voice:(+90)312 4552186



This archive was generated by hypermail 2b29 : Sun Aug 04 2002 - 04:13:08 EDT