ACL Scaling
For each ACL type, there is a software limit to the number of ACLs supported. The maximum number of ACL rules supported also varies with the device. The following table contains scaling information for all ICX devices.
ACL Rule Scaling Limits
| Security Feature | ICX 7850 | ICX 7750 | ICX 7650 | ICX 7550 | ICX 7450 | ICX 7250 | ICX 7150 |
|---|---|---|---|---|---|---|---|
| Software Scale | |||||||
| Maximum configurable standard numbered IPv4 ACLs | 99 | 99 | 99 | 99 | 99 | 99 | 99 |
| Maximum configurable extended numbered IPv4 ACLs | 100 | 100 | 100 | 100 | 100 | 100 | 100 |
| Maximum configurable standard named IPv4 ACLs | 600 | 600 | 600 | 600 | 600 | 600 | 600 |
| Maximum configurable extended named IPv4 ACLs | 600 | 600 | 600 | 600 | 600 | 600 | 600 |
| Maximum configurable IPv6 ACLs | 600 | 600 | 600 | 600 | 600 | 600 | 600 |
| Maximum configurable MAC ACLs | 3072 | 3072 | 3072 | 3072 | 3072 | 3072 | 3072 |
| Maximum configurable filters per IP ACL (same as system max parameter ip-filter-port) | 2,048 | 2,048 | 2,048 | 2,048 | 2,048 | 2,048 | 2,048 |
| Maximum configurable IP filters (IPv4 and IPv6) for the entire stack (including SPX) across all ACLs (same as system max parameter ip-filter-sys) | 8,192 | 8,192 | 8,192 | 8,192 | 8,192 | 8,192 | 8,192 |
| Maximum configurable filters per MAC ACL (same as system max parameter mac-filter-port) | 256 | 256 | 256 | 256 | 256 | 256 | 256 |
| Maximum configurable MAC filters for the entire stack (including SPX) across all ACLs (same as system max parameter mac-filter-sys) | 3,072 | 3,072 | 3,072 | 3,072 | 3,072 | 3,072 | 3,072 |
| Hardware Scale | |||||||
| IPv4 ingress TCAM rules per PP device (IPv4 ACL/IPSG) | 1,536 | 2,048 | 4,096 | 2,048 | 2,816 | 3,072 | 512 |
| IPv6 ingress TCAM rules per PP device | 1,536 | 1,280 | 2,048 | 2,048 | 1,408 | 1,536 | 256 |
| IPv4 Egress TCAM rules per PP device | 512 | 256 | 256 | 256 | 256 | 256 | 128 |
| IPv6 Egress TCAM rules per PP device | 512 | 256 | 256 | 256 | 256 | 256 | 128 |
| L2 Ingress TCAM rules per PP device | 1,536 | 2,048 | 1,536 | 2,048 | 2,816 | 3,072 | 256 |
ACL Scaling Considerations
Keep the following items in mind when configuring ACLs.
- All platforms consume 1 TCAM space by default for egress IPv4 and IPv6 groups, which reduces the space available for rules by 1 for IPv4 and IPv6 egress ACLs.
- For a PE unit, the number of default rules for IPv4 or IPv6 egress ACLs depends on the number of SPX ports configured on the PE unit.
- On ICX 7550 and ICX 7850 devices, when an egress ACL is applied to a VLAN, every ACL rule, including each default rule, is programmed as 2 entries.
- By default, TCAM reserves 5 entries for an IPv4 ingress ACL group and 30 entries for a Layer 2 (MAC) ingress ACL on all ICX platforms.
- Use the
show access-list tcam usage unitid command to review hardware usage before binding an ACL.device(config)# show access-list tcam usage unit 3 UnitId Region Group Id Direction Type : Allocated Total Free ------ ------ -------- --------- ---- : --------- ----- ---- 3 0 1 Pre-Ingres L2_IPv4 FIlters : 2 256 254 3 0 2 Pre-Ingres VCAP_MISC : 8 512 504 3 0 3 Ingress IPv4 Filters : 5 2048 2043 3 0 4 Ingress IPv6 Filters : 0 1280 1280 3 0 5 Ingress L2 Filters : 30 2048 2018 3 0 6 Ingress ICAP All Combo : 51 1024 973 3 0 7 Egress IPv4 Filters : 1 256 255 3 0 8 Egress IPv6 Filters : 1 256 255 3 0 9 Egress L2 Filters : 3 256 253
- Published scale numbers are one dimensional. If IPv4, IPv6, and MAC ACLs are cofigured on the same device, one-dimensional scaling numbers do not apply to the combined ACLs.
- On an ICX 7850 device, if you migrate to FastIron 08.0.95 or a later release from a FastIron 08.0.92 configuration that contains an IPv4 egress ACL applied to a virtual interface, the 2 TCAM rules originally programmed for the ACL (one ACL rule and one implicit deny rule), are programmed as 4 TCAM rules in the target release configuration, where the ACL will be applied at the VLAN level; that is, 2 rules for the ACL and 2 rules for the implicit deny rule.
- On an ICX 7850 device, if you migrate from FastIron 08.0.92 to FastIron 08.0.95 or a later release, the rules created for an IPv6 egress ACL applied to a virtual interface multiply. For example, if you created the original IPv6 egress ACL with one rule, the ACL is programmed as 4 rules in TCAM for the FastIron 08.0.92 configuration; that is, 1 IPv6 ACL rule and 3 implicit rules. In the resulting configuration for the target release, the IPv6 ACL is applied at the VLAN level, and a total of 8 rules will be created in TCAM; that is, 2 ACL rules and 6 implicit rules.
Note: On ICX 7850 devices, there is no change in scale when you apply an egress ACL on a
physical interface.