[c-nsp] 6500 acl log & cpu hit

Phil Mayers p.mayers at imperial.ac.uk
Tue Sep 16 06:56:43 EDT 2008


All,

We've recently disabled OAL because we had to enable VACL capture.

Without OAL, can I ensure a stray "log" ACL statement won't kill the 
box? Can I use one of the MLS rate limiters to throttle it?

The obvious ones seem to be:

ACL VACL LOG - set to "on, 2000pps"

ICMP UNREAC. ACL-DROP - set to "on, 0pps" as OAL wanted this

Or does ACL "log" traffic hit the CoPP limiters?


More information about the cisco-nsp mailing list