Debugging Cartage Application ACLs 78
ACLs can be acclimated to alter cartage on a router. Active debugs on a router is ability arresting and could
potentially use about all arrangement resources, such as anamnesis and processing power. Excessive debugging under
high amount altitude may account abrupt interruptions or in some cases account the accessory to crash. Therefore,
debugging commands charge to be acclimated with acute caution. Afore enabling debugging, audit the CPU load
by application the appearance processes cpu command and verify that acceptable CPU is accessible afore active the
debugs.
One way of abbreviation the appulse of the alter command on a accessory is to use an ACL to selectively ascertain the
traffic belief that needs to be examined. This abstraction does not do any packet filtering; it is acclimated alone for
controlled monitoring. Example 2-9 shows a agreement that enables debugging alone for packets amid the
hosts 10.1.1.1 and 192.168.1.1 application the alter ip packet [detail]
Example 2-9. Debugging Cartage Application ACL Example
Router(config)# access-list 101 admittance ip host 10.1.1.1 host 192.168.1.1
Router(config)# access-list 101 admittance ip host 192.168.1.1 host 10.1.1.1
Router(config)# end
Router# alter ip packet detail 101
IP packet debugging is on (detailed) for admission account 101
Caution
On the router console, back debugs are running, usually the router alert is not apparent because debugs
tend to annal actual fast on the animate screen, abnormally back the alter is intensive. However, use the
no alter all or undebug all commands to stop the debugs (Type this command as blind-folded.) For
more advice on cautiously application debugs, visit
http://www.cisco.com/en/US/tech/tk801/tk379/technologies_tech_note09186a008017874c.shtml
Summary
ACLs are the best accepted and bargain adjustment accessible for clarification cartage beyond the network. This
chapter primarily focused on the use of ACLs for cartage filtering. An overview of IP addressing, subnets, and
masks was additionally presented to advice you bigger accept the accomplishing of ACL. A above allotment of this
chapter was adherent to several types of ACLs and their applications. All Cisco IOS software versions are capable
of acknowledging ACLs.
References
http://www.iana.org/ipaddress/ip-addresses.htm
http://www.freesoft.org/CIE/Topics/26.htm
http://www.isoc.org/briefings/021/
http://www.cisco.com/en/US/products/ps6350/products_configuration_guide_chapter09186a00800ca7c0.html
http://www.cisco.com/en/US/products/sw/secursw/ps1018/products_tech_note09186a00800a5b9a.shtml
http://www.cisco.com/en/US/tech/tk827/tk369/technologies_white_paper09186a00800949b8.shtml
http://www.cisco.com/en/US/tech/tk583/tk822/technologies_tech_note09186a0080094524.shtml
http://www.cisco.com/en/US/products/sw/iosswrel/ps1835/products_configuration_guide_chapter09186a008030c799.html#http://www.cisco.com/en/US/products/sw/iosswrel/ps1834/products_feature_guide09186a0080080374.html
http://www.cisco.com/en/US/tech/tk648/tk361/technologies_white_paper09186a00801a1a55.shtml
http://www.cisco.com/en/US/products/ps6350/products_configuration_guide_chapter09186a0080431056.html
http://www.cisco.com/en/US/tech/tk648/tk361/technologies_white_paper09186a00801afc76.shtml