Requirements for using ACL Logging
The switch configuration must include an ACL (1) assigned to a port, trunk, or static VLAN interface and (2) containing an ACE configured with the deny or permit action and the log option.
If the RACL application is used, then IPv4 routing must be enabled on the switch.
- For ACL logging to a server:
The server must be accessible to the switch and identified in the running configuration.
The logging facility must be enabled for.
- Debug must be configured to:
support ACL messages
send debug messages to the desired debug destination
For more information, see Enabling ACL logging on the switch.