Displaying TCAM Information for ACLs
You can use different forms of the
show access-list tcam command to display information on the following items:
- IPv4 ACLs
- IPv6 ACLs
- MAC ACLs
- ACLs applied to an interface or LAG
- ACLs applied to a stack unit
- ACLs applied to incoming traffic
- ACLs applied to outbound traffic
- Statistics on ACL rules stored in TCAM
Refer to the following examples for more information.
The following example provides TCAM information
for ACL 136. The show
access-list tcam acl-name command shows which ports have
the ACL programmed in TCAM, the type of ACL, which direction the ACL is applied,
and how
many rules, including the default rule, are programmed in TCAM for the ACL.
device(config-vlan-222)# show access-list tcam acl-name 136 Ingress UnitId Feature SRule ERule Filters Contiguous RefCnt Bind If ------ ------- ----- ----- ------- ---------- ------ ------- 1 UACL-IPv4 1123 2125 1003 YES 1 e 1/1/18 2 UACL-IPv4 1123 2125 1003 YES 1 e 2/1/18
The following example provides detailed information for the same ACL. The detailed information includes ACL rules and associated ACL sequence numbers and ports.
device(config-vlan-222)# show access-list tcam acl-name 136 detail Ingress: UnitId Region Feature Filter ID Rule RefCnt Bind If ------ ------ ------- --------- ----- ------ ------- 1 0 UACL-IPv4 8 1123 1 e 1/1/18 1 0 UACL-IPv4 10 1124 1 e 1/1/18 1 0 UACL-IPv4 20 1125 1 e 1/1/18 1 0 UACL-IPv4 30 1126 1 e 1/1/18 1 0 UACL-IPv4 40 1127 1 e 1/1/18 1 0 UACL-IPv4 50 1128 1 e 1/1/18 1 0 UACL-IPv4 60 1129 1 e 1/1/18 1 0 UACL-IPv4 70 1130 1 e 1/1/18 1 0 UACL-IPv4 80 1131 1 e 1/1/18
The following example displays information on TCAM rules for the IPv6 ACL named vlan333-ipv6.
device(config-vlan-333)# show running-config vlan 333 vlan 333 by port tagged ethe 1/1/10 ethe 2/1/10 ethe 3/1/10 lag 25 router-interface ve 333 ipv6 access-group vlan333-ipv6 in <-- Applied VLAN shown in output ip access-group vlan333-ipv4 in ip access-group frag deny ! ! device(config-vlan-333)# show access-list tcam acl-name vlan333-ipv6 Ingress: UnitId Feature SRule ERule Filters Contiguous RefCnt Bind If ------ ------- ----- ----- ------- ---------- ------ ------- 1 UACL-IPv6 641 786 146 YES 1 e 1/1/10 2 UACL-IPv6 1012 1157 146 YES 2 e 2/1/10 e 2/1/38 3 UACL-IPv6 1147 1292 146 YES 2 e 3/1/10 e 3/1/40 device(config-vlan-333)#
The following example shows detailed TCAM information for the same ACL.
device(config-vlan-333)# show access-list tcam acl-name vlan333-ipv6 detail Ingress: UnitId Region Feature Filter ID Rule RefCnt Bind If ------ ------ ------- --------- ----- ------ ------- 1 0 UACL-IPv6 1 641 1 e 1/1/10 1 0 UACL-IPv6 2 642 1 e 1/1/10 1 0 UACL-IPv6 3 643 1 e 1/1/10 1 0 UACL-IPv6 6 644 1 e 1/1/10 1 0 UACL-IPv6 12 645 1 e 1/1/10 1 0 UACL-IPv6 13 646 1 e 1/1/10 1 0 UACL-IPv6 14 647 1 e 1/1/10
The following example breaks out TCAM rule information for a MAC ACL found in the running configuration for VLAN 333.
device(config-vlan-333)# show running-config vlan 333 vlan 333 by port tagged ethe 1/1/10 ethe 2/1/10 ethe 3/1/10 lag 25 router-interface ve 333 ipv6 access-group vlan333-ipv6 in mac access-group mac_acl in ip access-group vlan333-ipv4 in ip access-group frag deny ! ! device(config-vlan-333)# show access-list tcam acl-name mac_acl Ingress: UnitId Feature SRule ERule Filters Contiguous RefCnt Bind If ------ ------- ----- ----- ------- ---------- ------ ------- 1 UACL-MAC 1119 1129 11 YES 1 e 1/1/10 2 UACL-MAC 1490 1500 11 YES 2 e 2/1/10 e 2/1/38 3 UACL-MAC 1625 1635 11 YES 2 e 3/1/10 e 3/1/40 device(config-vlan-333)#
device(config-vlan-333)# show access-list tcam acl-name mac_acl detail Ingress: UnitId Region Feature Filter ID Rule RefCnt Bind If ------ ------ ------- --------- ----- ------ ------- 1 0 UACL-MAC 10 1119 1 e 1/1/10 1 0 UACL-MAC 20 1120 1 e 1/1/10 1 0 UACL-MAC 30 1121 1 e 1/1/10 1 0 UACL-MAC 40 1122 1 e 1/1/10 1 0 UACL-MAC 50 1123 1 e 1/1/10 1 0 UACL-MAC 60 1124 1 e 1/1/10 1 0 UACL-MAC 70 1125 1 e 1/1/10 1 0 UACL-MAC 80 1126 1 e 1/1/10 1 0 UACL-MAC 90 1127 1 e 1/1/10 1 0 UACL-MAC 100 1128 1 e 1/1/10 1 0 UACL-MAC 65001 1129 1 e 1/1/10 2 0 UACL-MAC 10 1490 2 e 2/1/10 e 2/1/38 ^C device(config-vlan-333)#
The following example displays TCAM usage for a specified stack unit. Information includes available TCAM space for IPv4, IPv6, and MAC ACLs. For a dual-PP device, the command output includes information on the region (0 or 1).
device# show access-list tcam usage unit 4 UnitId Region Group Id Direction Type : Allocated Total Free ------ ------ -------- --------- ---- : --------- ----- ---- 4 0 1 Pre-Ingres L2_IPv4 FIlters : 1 512 511 4 0 2 Pre-Ingres VCAP_MISC : 0 1024 1024 4 0 3 Ingress IPv4 Filters : 9 2816 2807 <-- 4 0 4 Ingress IPv6 Filters : 0 1408 1408 <-- 4 0 5 Ingress L2 Filters : 30 2816 2786 <-- 4 0 6 Ingress ICAP All Combo : 51 768 717 4 0 7 Ingress IPSec Filters : 0 1408 1408 4 0 8 Egress IPv4 Filters : 0 256 256 <-- 4 0 9 Egress IPv6 Filters : 0 256 256 <-- 4 0 10 Egress L2 Filters : 3 256 253 <-- 4 1 1 Pre-Ingres L2_IPv4 FIlters : 1 512 511 4 1 2 Pre-Ingres VCAP_MISC : 0 1024 1024 4 1 3 Ingress IPv4 Filters : 1031 2816 1785 4 1 4 Ingress IPv6 Filters : 7 896 889 4 1 6 Ingress ICAP All Combo : 51 512 461 4 1 7 Ingress IPSec Filters : 0 896 896 4 1 8 Egress IPv4 Filters : 4 256 252 4 1 9 Egress IPv6 Filters : 247 256 9 4 1 10 Egress L2 Filters : 3 256 253 device#
The following example displays TCAM information for a specified interface. Use this command to verify ACLs applied on an interface and how many filters are programmed in TCAM for each ACL.
device# show access-list tcam interface ethernet 4/1/10 Ingress: UnitId AclName Feature SRule ERule Filters Contiguous Merged Acl ------ ------- ------- ----- ----- ------- ---------- --------- 4 STK_ZTP_0403 ZTP 36 36 1 YES 4 STK_IPC_0401 STK_HIGIG 5 5 1 YES 4 123 UACL-IPv4 84 104 21 YES 4 mac_acl UACL-MAC 105 115 11 YES Egress: UnitId AclName Feature SRule ERule Filters Contiguous Merged Acl ------ ------- ------- ----- ----- ------- ---------- --------- 4 140 UACL-IPv4 128 129 2 YES 4 egress UACL-IPv6 118 127 10 YES
The following example displays more detailed information for the same interface, including all rules and filters (by sequence number) for each ACL bound to the interface.
device# show access-list tcam interface ethernet 4/1/10 detail Ingress: UnitId Region AclName Feature Filter Id Rule ------ ------ ------- ------- --------- ----- 4 1 STK_ZTP_0403 ZTP 1 36 4 1 STK_IPC_0401 STK_HIGIG 1 5 4 1 123 UACL-IPv4 10 84 4 1 123 UACL-IPv4 20 85 4 1 123 UACL-IPv4 30 86 4 1 123 UACL-IPv4 40 87 4 1 123 UACL-IPv4 50 88
The following example displays TCAM information for a specified LAG interface.
device# show access-list tcam interface lag 8060 Ingress: UnitId AclName Feature SRule ERule Filters Contiguous Merged Acl ------ ------- ------- ----- ----- ------- ---------- --------- 2 qos_dscp_34 QOS-DSCP/PCP 909 909 1 YES 3 qos_dscp_34 QOS-DSCP/PCP 907 907 1 YES Egress: UnitId AclName Feature SRule ERule Filters Contiguous Merged Acl ------ ------- ------- ----- ----- ------- ---------- --------- 2 125 UACL-IPv4 1587 1822 236 YES 2 egress UACL-IPv6 1823 2026 204 YES 3 125 UACL-IPv4 1585 1820 236 YES 3 egress UACL-IPv6 1821 2024 204 YES device#
The following example displays detailed information for a specified LAG.
device# show access-list tcam interface lag 8060 detail Ingress: UnitId Region AclName Feature Filter Id Rule ------ ------ ------- ------- --------- ----- 2 0 qos_dscp_34 QOS-DSCP/PCP 10 909 3 0 qos_dscp_34 QOS-DSCP/PCP 10 907 Egress: UnitId Region AclName Feature Filter Id Rule ------ ------ ------- ------- --------- ----- 2 0 125 UACL-IPv4 2 1587 2 0 125 UACL-IPv4 110 1588 2 0 125 UACL-IPv4 120 1589
The following example displays a list of all ACLs and associated rules, including default rules, programmed on unit 1 in an inbound direction.
device# show access-list tcam ingress unit 1 Ingress: UnitId AclName Feature SRule ERule Filters Contiguous RefCnt Bind If ------ ------- ------- ----- ----- ------- ---------- ------ ------- 1 SFLOW_RULE SFLOW 34 34 1 YES 30 e 1/1/1 to 1/1/24 e 1/2/2 e 1/2/4 to 1/2/8 1 INGRESS_CPU_RULE CPU_RULES 5 5 1 YES 33 e 1/1/1 to 1/1/24 e 1/2/1 to 1/2/8 1 MANAGEMENT UACL-IPv4 3165 3356 192 YES 1 e 1/1/2 1 SYS_MGMT_VLAN VLAN 6 6 1 YES 30 e 1/1/1 to 1/1/24 e 1/2/2 e 1/2/4 to 1/2/8 1 SYSTEM-L3-UDP-BC UDP_BC 35 35 1 YES 30 e 1/1/1 to 1/1/24 e 1/2/2 e 1/2/4 to 1/2/8 1 SPX_ZTP_0402 SPX_IPC_MAC 36 36 1 YES 30 e 1/1/1 to 1/1/24 e 1/2/2 e 1/2/4 to 1/2/8 1 STK_ZTP_0403 ZTP 37 37 1 YES 30 e 1/1/1 to 1/1/24 e 1/2/2 e 1/2/4 to 1/2/8 1 STK_IPC_0401 STK_HIGIG 7 7 1 YES 30 e 1/1/1 to 1/1/24 e 1/2/2 e 1/2/4 to 1/2/8 1 MCAST_ACL_RULES_IGMP IGMP 38 38 1 YES 30 e 1/1/1 to 1/1/24 e 1/2/2 e 1/2/4 to 1/2/8 1 MCAST_ACL_RULES_PIM_V4 PIMV4 39 39 1 YES 30 e 1/1/1 to 1/1/24 e 1/2/2 e 1/2/4 to 1/2/8 1 MCAST_ACL_RULES_RES_MC_V4 RES_MC_V4 40 40 1 YES 30 e 1/1/1 to 1/1/24 e 1/2/2 e 1/2/4 to 1/2/8 1 MCAST_ACL_RULES_SC_SP_MLD_V1 MLD 41 41 2 YES 30 e 1/1/1 to 1/1/24 e 1/2/2 e 1/2/4 to 1/2/8 1 MCAST_ACL_RULES_SC_SP_MLD_V2 MLD 44 44 1 YES 30 e 1/1/1 to 1/1/24 e 1/2/2 e 1/2/4 to 1/2/8 1 MCAST_ACL_RULES_SC_SP_PIM_V6 PIMV6 45 45 1 YES 30 e 1/1/1 to 1/1/24 e 1/2/2 e 1/2/4 to 1/2/8 1 SYS_CPU_VLAN_BPDU VLAN 46 46 1 YES 1 1 SYS_PVST XSTP 47 47 1 YES 30 e 1/1/1 to 1/1/24 e 1/2/2 e 1/2/4 to 1/2/8 1 SYS_MRP MRP 8 8 1 YES 30 e 1/1/1 to 1/1/24 e 1/2/2 e 1/2/4 to 1/2/8 1 SYS_UDLD UDLD 9 9 1 YES 30 e 1/1/1 to 1/1/24 e 1/2/2 e 1/2/4 to 1/2/8 1 SYS_EOAM_LOOPBACK EOAM 48 48 1 YES 30 e 1/1/1 to 1/1/24 e 1/2/2 e 1/2/4 to 1/2/8 1 SYS_SMAC_SUP FDB 10 10 1 YES 30 e 1/1/1 to 1/1/24 e 1/2/2 e 1/2/4 to 1/2/8 1 SYSTEM-L3-IPV6-RES-MC IPV6_RES_MC 49 49 1 YES 30 e 1/1/1 to 1/1/24 e 1/2/2 e 1/2/4 to 1/2/8 1 SYSTEM-L3-IRDP IRDP 1 1 1 YES 30 e 1/1/1 to 1/1/24 e 1/2/2 e 1/2/4 to 1/2/8 1 SYSTEM-L3-ARP-PRIORITY ARP 11 11 1 YES 30 e 1/1/1 to 1/1/24 e 1/2/2 e 1/2/4 to 1/2/8 1 FLEXAUTH_802.1X_BPDU_RULE_UNIT_1 FLEXAUTH 50 50 1 YES 30 e 1/1/1 to 1/1/24 e 1/2/2 e 1/2/4 to 1/2/8 1 SYS_PROTO_REPRIO L2_PROTO 51 52 2 YES 30 e 1/1/1 to 1/1/24 e 1/2/2 e 1/2/4 to 1/2/8 1 L2MCAST-ACL-RULES-SPATHA-SICA-UMC-V6 MC_UMC 53 55 3 YES 30 e 1/1/1 to 1/1/24 e 1/2/2 e 1/2/4 to 1/2/8 1 SYSTEM-L3-ND ND 56 58 3 YES 30 e 1/1/1 to 1/1/24 e 1/2/2 e 1/2/4 to 1/2/8 1 scale22 UACL-IPv6 2357 3160 804 YES 2 e 1/1/11 e 1/2/2 1 131 UACL-IPv4 3161 3164 4 YES 2 e 1/1/11 e 1/2/2
The following example displays TCAM information for ACLs applied in an outbound direction on unit 1. The command output shows all ACLs programmed in TCAM for the specified unit in the specified direction, including system default rules.
device# show access-list tcam egress unit 1 Egress: UnitId AclName Feature SRule ERule Filters Contiguous RefCnt Bind If ------ ------- ------- ----- ----- ------- ---------- ------ ------- 1 ECPU_PORTID_RULE CPU_RULES 84 85 2 YES 1 1 ECPU_CLASSID_RULE CPU_RULES 86 86 1 YES 1 device#
The show access-list tcam
rule-statistics command is used to display hardware-level accounting
statistics. The output is displayed for a specific rule in a specific region on
a
specific unit.
device# show access-list tcam rule-statistics 3161 unit 1 region 0 Rule: 3161 Stat: 0 device#
The
show access-list tcam rule command displays detailed output for each rule programmed in TCAM. The command is
local to each unit. The following example displays information on rules for region
0 of unit 1.
device# show access-list tcam rule 3161 unit 1 region 0
EID 0x00000c59: gid=0x3,
slice=0, slice_idx=0xc9, part =0 prio=0x1fe0216, flags=0x210602, Installed, Enabled
tcam: color_indep=1,
StageIngress
InPorts
DATA=0x0000000000000000000000000000000000000000000000000008000000000800
MASK=0x00000000000000000000000000000000000000000000000003fe000001ffffff
Stage
IpType
Offset0: 325 Width0: 4
DATA=0x00000000
MASK=0x0000000e
InterfaceClassL2
Offset0: 32 Width0: 12
DATA=0x0000000e
MASK=0x00000fff
action={act=CosQCpuNew, param0=31(0x1f), param1=0(0x00), param2=0(0x00), param3=0(0x00)}
action={act=SwitchToCpuCancel, param0=0(0x00), param1=0(0x00), param2=0(0x00), param3=0(0x00)}
action={act=DynamicHgTrunkCancel, param0=0(0x00), param1=0(0x00), param2=0(0x00), param3=0(0x00)}
action={act=Drop, param0=0(0x00), param1=0(0x00), param2=0(0x00), param3=0(0x00)}
policer=
statistics={stat id 3079 slice = 6 idx=0 entries=1}{Packets}{Bytes}
device#