ACL Scaling

For each ACL type, there is a software limit to the number of ACLs supported. The maximum number of ACL rules supported also varies with the device. The following table contains scaling information for all ICX devices.

ACL Rule Scaling Limits
Do the values for the 8200 devices also apply to the 8100 devices? Yes

Security Feature ICX 8200 ICX 8100 ICX 7850 ICX 7650 ICX 7550
Software Scale
Maximum configurable standard numbered IPv4 ACLs 99 99 99 99 99
Maximum configurable extended numbered IPv4 ACLs 100 100 100 100 100
Maximum configurable standard named IPv4 ACLs 600 600 600 600 600
Maximum configurable extended named IPv4 ACLs 600 600 600 600 600
Maximum configurable IPv6 ACLs 600 600 600 600 600
Maximum configurable MAC ACLs 3,072 3,072 3,072 3,072 3,072
Maximum configurable filters per IP ACL (same as system max parameter ip-filter-port) 2,048 2,048 2,048 2,048 2,048
Maximum configurable IP filters (IPv4 and IPv6) for the entire stack across all ACLs (same as system max parameter ip-filter-sys) 8,192 8,192 8,192 8,192 8,192
Maximum configurable filters per MAC ACL (same as system max parameter mac-filter-port) 256 256 256 256 256
Maximum configurable MAC filters for the entire stack across all ACLs (same as system max parameter mac-filter-sys) 3,072 3,072 3,072 3,072 3,072
DHCP Snooping/IPSG/DAI
Max DHCP Snooping entries 32,768 32,768 32,768 32,768 32,768
Max number of IP Source Guard entries per device 1,0241 1,0242 1,536 4,096 2,048
Max Dynamic ARP Inspection entries 32,768 32,768 32,768 32,768 32,768
Max Static ARP Inspection entries 6,000 6,000 6,000 6,000 6,000
Maximum configurable filters per SG  ACL 8 8 8 8 8
DHCPv6 Snooping/ND Inspection
Max DHCPv6 Snooping entries 32,768 32,768 32,768 32,768 16,384
Max IPv6 Neighbor Discovery Inspection entries 32,768 32,768 32,768 32,768 16,384
Max Static IPv6 Neighbor Discovery Inspection entries 6,000 6,000 6,000 6,000 6,000
Max IPv6 Source Guard Entries per device 512 512 1,536 2,048 2,048
Hardware Scale
IPv4 ingress TCAM rules per device (IPv4 ACL/IPSG) 102434 10244 1,536 4,096 2,048
IPv6 ingress TCAM rules per device 51256 5126 1,536 2,048 2,048
IPv4 Egress TCAM rules per device 128 128 512 256 256
IPv6 Egress TCAM rules per device 128 128 512 256 256
L2 Ingress TCAM rules per device 512 512 1,536 1,536 2,048

ACL Scaling Considerations

Keep the following items in mind when configuring ACLs.

Is there any exception for 8100 devices? No
  • All platforms consume 1 TCAM space by default for egress IPv4 and IPv6 groups, which reduces the space available for rules by 1 for IPv4 and IPv6 egress ACLs.
  • ICX 8100 and ICX 8200 devices consume 1 TCAM space by default for all groups.
  • On ICX 7550 and ICX 7850 devices, when an egress ACL is applied to a VLAN, every ACL rule, including each default rule, is programmed as 2 entries.
  • By default, TCAM reserves 5 entries for an IPv4 ingress ACL group and 30 entries for a Layer 2 (MAC) ingress ACL on all ICX platforms.
  • Use the show access-list tcam usage unit id command to review hardware usage before binding an ACL.

    Example:

    device(config)# show access-list tcam usage unit 3
    UnitId Region Group Id   Direction       Type                : Allocated  Total      Free      
    ------ ------ --------   ---------       ----                : ---------  -----      ----      
    3      0      1          Pre-Ingres      L2_IPv4 FIlters     : 2          256        254       
    3      0      2          Pre-Ingres      VCAP_MISC           : 8          512        504       
    3      0      3          Ingress         IPv4 Filters        : 5          2048       2043      
    3      0      4          Ingress         IPv6 Filters        : 0          1280       1280      
    3      0      5          Ingress         L2 Filters          : 30         2048       2018      
    3      0      6          Ingress         ICAP All Combo      : 51         1024       973       
    3      0      7          Egress          IPv4 Filters        : 1          256        255       
    3      0      8          Egress          IPv6 Filters        : 1          256        255       
    3      0      9          Egress          L2 Filters          : 3          256        253       
    
    

  • Published scale numbers are one dimensional. If IPv4, IPv6, and MAC ACLs are configured on the same device, one-dimensional scaling numbers do not apply to the combined ACLs.
  • On an ICX 7850 device, if you migrate to FastIron 08.0.95 or a later release from a FastIron 08.0.92 configuration that contains an IPv4 egress ACL applied to a virtual interface, the 2 TCAM rules originally programmed for the ACL (one ACL rule and one implicit deny rule), are programmed as 4 TCAM rules in the target release configuration, where the ACL will be applied at the VLAN level; that is, 2 rules for the ACL and 2 rules for the implicit deny rule.
  • On an ICX 7850 device, if you migrate from FastIron 08.0.92 to FastIron 08.0.95 or a later release, the rules created for an IPv6 egress ACL applied to a virtual interface multiply. For example, if you created the original IPv6 egress ACL with one rule, the ACL is programmed as 4 rules in TCAM for the FastIron 08.0.92 configuration; that is, 1 IPv6 ACL rule and 3 implicit rules. In the resulting configuration for the target release, the IPv6 ACL is applied at the VLAN level, and a total of 8 rules will be created in TCAM; that is, 2 ACL rules and 6 implicit rules.
    Note: On ICX 7850 devices, there is no change in scale when you apply an egress ACL on a physical interface.
  1. The maximum number of IPv4 Source Guard Entries per ICX 8100-C08PF device is 512. The maximum number of IPv6 Source Guard Entries per ICX 8100-C08PF device is 256. ↩
  2. The maximum number of IPv4 Source Guard Entries per ICX 8200-C08PF device is 512. The maximum number of IPv6 Source Guard Entries per ICX 8200-C08PF device is 256. ↩
  3. ICX 8100-C08PF devices support 512 IPv4 ingress TCAM rules (IPv4 ACL) per device. ↩
  4. ICX 8200-C08PF devices support 512 IPv4 ingress TCAM rules (IPv4 ACL) per device. ↩
  5. ICX 8100-C08PF devices support 256 IPv6 ingress TCAM rules (IPv6 ACL) per device. ↩
  6. ICX 8200-C08PF devices support 256 IPv6 ingress TCAM rules (IPv6 ACL) per device. ↩