Access Security Guide K/KA/KB.15.15

Example 9 Resetting ACE hit counters to Zero
The following example uses the counter activity in figure 10–47 to demonstrate using clear
statistics to reset the counters to zero.
Figure 212 IPv6 ACL performance monitoring output after zero
Using IPv6 counters with multiple interface assignments
Where the same IPv6 ACL is assigned to multiple interfaces, the switch maintains a separate
instance of each ACE counter in the ACL. When there is a match with traffic on one of the ACL's
assigned interfaces, only the affected ACE counters for that interface are incremented. Other
instances of the same ACL applied to other interfaces are not affected.
NOTE: These examples of counters use small values to help illustrate counter operation. The
counters in real-time network applications are generally much more active and show higher values.
For example, suppose that:
An ACL named "V6-01" is configured as shown in Figure 213 (page 298) to block Telnet
access to a workstation at FE80::20:2, which is connected to a port belonging to VLAN 20.
The ACL is assigned as a PACL (port ACL) on port B2, which is also a member of VLAN 20:
Figure 213 ACL "V6-01" and command for PACL assignment on port B2
298 IPv4 Access Control Lists (ACLs)