Read-only commands #
Read-only commands
Cisco IOS XE · Authorized EXEC mode; context specified below
Replace these example values: GigabitEthernet0/0/0.
show ip interface GigabitEthernet0/0/0Replace these example values: GigabitEthernet0/0/0.
show running-config interface GigabitEthernet0/0/0Output may contain sensitive operational data.Replace these example values: EDGE-IN.
show ip access-lists EDGE-INReplace these example values: EDGE-IN.
show access-lists EDGE-INCatalyst 9300-style hardware view #
Catalyst 9300-style hardware view
Cisco IOS XE · Authorized EXEC mode; context specified below
show platform software fed switch active acl counters hardwareSome Catalyst 9500 platforms use this form instead #
Some Catalyst 9500 platforms use this form instead
Cisco IOS XE · Authorized EXEC mode; context specified below
show platform software fed active acl counters hardwareUse the form supported by your exact platform; the extra switch keyword is not universal. These displays provide aggregate hardware statistics, not a guaranteed per-rule packet count.
Workflow #
- Describe one flow with source, destination, protocol, ports and direction. For an ICMP problem, record the relevant message type rather than inventing TCP or UDP ports.
- Establish the routed path. Locate the interface that the packet actually enters or leaves and inspect its inbound and outbound ACL attachments.
- Read the applicable ACL in order. Find the first matching entry, including address wildcards and protocol conditions. An ACL's presence in the configuration does not show that the affected interface uses it.
- Save counters before and after a narrowly timed reproduction of the symptom. Preserve existing counters so the change remains reviewable without losing earlier evidence.
- On hardware-forwarding switches, correlate the software view with the supported hardware view. Use the interval and other traffic on the switch to judge how strongly an aggregate change relates to your test.
Interpretation pitfalls #
An aggregate drop increase supports further investigation but does not uniquely identify one ACL entry. Shared policies and unrelated traffic can contribute during the same observation interval. The absence of a visible per-entry increment can be a measurement limitation rather than a rule-order problem.
The final implicit denial may not appear as an ordinary numbered entry. Also keep security filtering separate from ACLs used to classify traffic for NAT or another feature: the same permit/deny vocabulary does not make every ACL a packet filter applied to an interface.
Evidence to save #
Keep the flow description, actual attachment and direction, ordered rules and synchronized counter samples together. Do not add broad permits, enable extensive logging or clear shared counters merely to make the diagnosis easier. The first goal is to identify the relevant policy and measurement point accurately.
Useful tools and references #
- Wildcard mask calculator: Check the address matches intended by a wildcard expression before evaluating ACL rule order.
- Common TCP and UDP ports: Look up a service's customary protocol and port, then verify the actual application flow rather than assuming it uses the default.
Sources
Documentation reviewed: 8 October 2026