Cisco Bug: CSCvs32101 - SGACL not hitting when IP Source guard is applied on source and destination interface.
Jan 09, 2020
- Cisco IOS
Known Affected Releases
Symptom: Ip verify source is used to dynamically create ACLs on a per-port basis (these can't be viewed in the running-configuration). Any traffic which doesn't match the binding entries is dropped in hardware. However, the port won't go into the err disable state ? it won't even display a violation message at the console. After Applying "ip verify source" to interfaces all SGACL denied traffic is allowed Conditions: entries present in ip source binding and sh ip verify source
Bug details contain sensitive information and therefore require a Cisco.com account to be viewed.
Bug Details Include
- Full Description (including symptoms, conditions and workarounds)
- Known Fixed Releases
- Related Community Discussions
- Number of Related Support Cases