Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    command to monitor acl activity?

    Scheduled Pinned Locked Moved TNSR
    6 Posts 2 Posters 583 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • G
      gabacho4 Rebel Alliance
      last edited by

      I'm working on configuring a TNSR instance and, as I go about setting up various ACLs, was hoping to be able to do something like ping a device on the network and view the permit/deny/reflect ACL activity on the router. I've cannot find a show command that does this but it's entirely possible I've missed it. This would be very helpful for instances where things don't respond as I would expect them to. Any utility/command that I can leverage?

      1 Reply Last reply Reply Quote 0
      • jimpJ
        jimp Rebel Alliance Developer Netgate
        last edited by

        I don't think there is anything which tracks that, even in the dataplane itself (VPP). There is a "count" field in ACLs inside VPP but it's the number of rules in an ACL, not hits. I don't see anything else close.

        You can look at how things are moving in VPP directly, using sudo vppctl and items in there like the trace command. Though it's nowhere near as easy as checking a hit counter.

        Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        1 Reply Last reply Reply Quote 1
        • G
          gabacho4 Rebel Alliance
          last edited by

          @jimp thanks again for your response and the helpful information. You've certainly given me something to read up on and play with! Any likelihood a counter type feature could/would be forthcoming at a later date?

          1 Reply Last reply Reply Quote 0
          • jimpJ
            jimp Rebel Alliance Developer Netgate
            last edited by

            We have some feature requests open for that and other similar things (like notifying on ACL hit) but no ETA on when that might be implemented.

            Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

            Need help fast? Netgate Global Support!

            Do not Chat/PM for help!

            1 Reply Last reply Reply Quote 0
            • G
              gabacho4 Rebel Alliance
              last edited by

              Alrighty then. I'll work on getting smarter while you all keep developing away. Is there anywhere I can go to see the outstanding feature requests/bugs/etc so that I don't bother you all with questions about things that are already known about or being worked on?

              1 Reply Last reply Reply Quote 0
              • jimpJ
                jimp Rebel Alliance Developer Netgate
                last edited by

                Not at the moment, it's all in an internal bug tracker. Every once in a while we revisit making that public but so far it's mostly private with internal chatter. If anything changes there, it will be in the release notes and related posts around a new release.

                Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

                Need help fast? Netgate Global Support!

                Do not Chat/PM for help!

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.