[c-nsp] matched ACL - counters not updating

Roland Dobbins rdobbins at arbor.net
Thu Jul 2 22:43:31 EDT 2009


On Jul 3, 2009, at 9:38 AM, Aaron Riemer wrote:

> It is a 6500 with a SUP2 however other extended ACL's are showing
> matches with each ACE.

This may indicate that the traffic in question is being punted; you  
may wish to verify via sh proc c sort | e 0.00 and sh fm sum.

> The traffic must be traversing this interface as it is the only way to
> route out the subnet.

Are you sure the traffic is in fact reaching the interface in the  
first place?

-----------------------------------------------------------------------
Roland Dobbins <rdobbins at arbor.net> // <http://www.arbornetworks.com>

         Unfortunately, inefficiency scales really well.

		   -- Kevin Lawton



More information about the cisco-nsp mailing list