Howdy,

Should ingress packets dropped by ACLs still hit Netflow on the GSR with E5 
linecards?

Gi2/0/2       10.1.123.32  Null          10.1.123.3   11 A29F 0035     1

Gi2/0/2 is one of our Internet connections
10.1.123.32 (changed to protect, is one of our routed public IPs that isn't 
routed in our network (spoofing?))
10.1.123.3 (changed to protect) is the IP address of one of our DNS servers.

So basically a packet is being sent in from the Internet sourced from one of my 
own IP addresses, and I assume it is being dropped because of the ACL on our 
Internet connections that says we don't want traffic coming in from ourselves, 
but why is it showing up in the netflow exports?

Thanks,
-Drew



_______________________________________________
cisco-nsp mailing list  [email protected]
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/

Reply via email to