ACL Scaling

For each ACL type, there is a software limit to the number of ACLs supported. The maximum number of ACL rules supported also varies with the device. The following table contains scaling information for all ICX devices.

ACL Rule Scaling Limits

Security Feature ICX 7850 ICX 7750 ICX 7650 ICX 7550 ICX 7450 ICX 7250 ICX 7150
Software Scale
Maximum configurable standard numbered IPv4 ACLs 99 99 99 99 99 99 99
Maximum configurable extended numbered IPv4 ACLs 100 100 100 100 100 100 100
Maximum configurable standard named IPv4 ACLs 600 600 600 600 600 600 600
Maximum configurable extended named IPv4 ACLs 600 600 600 600 600 600 600
Maximum configurable IPv6 ACLs 600 600 600 600 600 600 600
Maximum configurable MAC ACLs 3072 3072 3072 3072 3072 3072 3072
Maximum configurable filters per IP ACL (same as system max parameter ip-filter-port) 2,048 2,048 2,048 2,048 2,048 2,048 2,048
Maximum configurable IP filters (IPv4 and IPv6) for the entire stack (including SPX) across all ACLs (same as system max parameter ip-filter-sys) 8,192 8,192 8,192 8,192 8,192 8,192 8,192
Maximum configurable filters per MAC ACL (same as system max parameter mac-filter-port) 256 256 256 256 256 256 256
Maximum configurable MAC filters for the entire stack (including SPX) across all ACLs (same as system max parameter mac-filter-sys) 3,072 3,072 3,072 3,072 3,072 3,072 3,072
Hardware Scale
IPv4 ingress TCAM rules per PP device (IPv4 ACL/IPSG) 1,536 2,048 4,096 2,048 2,816 3,072 512
IPv6 ingress TCAM rules per PP device 1,536 1,280 2,048 2,048 1,408 1,536 256
IPv4 Egress TCAM rules per PP device 512 256 256 256 256 256 128
IPv6 Egress TCAM rules per PP device 512 256 256 256 256 256 128
L2 Ingress TCAM rules per PP device 1,536 2,048 1,536 2,048 2,816 3,072 256

ACL Scaling Considerations

Keep the following items in mind when configuring ACLs.

  • All platforms consume 1 TCAM space by default for egress IPv4 and IPv6 groups, which reduces the space available for rules by 1 for IPv4 and IPv6 egress ACLs.
  • For a PE unit, the number of default rules for IPv4 or IPv6 egress ACLs depends on the number of SPX ports configured on the PE unit.
  • On ICX 7550 and ICX 7850 devices, when an egress ACL is applied to a VLAN, every ACL rule, including each default rule, is programmed as 2 entries.
  • By default, TCAM reserves 5 entries for an IPv4 ingress ACL group and 30 entries for a Layer 2 (MAC) ingress ACL on all ICX platforms.
  • Use the show access-list tcam usage unitid command to review hardware usage before binding an ACL.

    Example:

    device(config)# show access-list tcam usage unit 3
    UnitId Region Group Id   Direction       Type                : Allocated  Total      Free      
    ------ ------ --------   ---------       ----                : ---------  -----      ----      
    3      0      1          Pre-Ingres      L2_IPv4 FIlters     : 2          256        254       
    3      0      2          Pre-Ingres      VCAP_MISC           : 8          512        504       
    3      0      3          Ingress         IPv4 Filters        : 5          2048       2043      
    3      0      4          Ingress         IPv6 Filters        : 0          1280       1280      
    3      0      5          Ingress         L2 Filters          : 30         2048       2018      
    3      0      6          Ingress         ICAP All Combo      : 51         1024       973       
    3      0      7          Egress          IPv4 Filters        : 1          256        255       
    3      0      8          Egress          IPv6 Filters        : 1          256        255       
    3      0      9          Egress          L2 Filters          : 3          256        253       
    
    

  • Published scale numbers are one dimensional. If IPv4, IPv6, and MAC ACLs are cofigured on the same device, one-dimensional scaling numbers do not apply to the combined ACLs.
  • On an ICX 7850 device, if you migrate to FastIron 08.0.95 or a later release from a FastIron 08.0.92 configuration that contains an IPv4 egress ACL applied to a virtual interface, the 2 TCAM rules originally programmed for the ACL (one ACL rule and one implicit deny rule), are programmed as 4 TCAM rules in the target release configuration, where the ACL will be applied at the VLAN level; that is, 2 rules for the ACL and 2 rules for the implicit deny rule.
  • On an ICX 7850 device, if you migrate from FastIron 08.0.92 to FastIron 08.0.95 or a later release, the rules created for an IPv6 egress ACL applied to a virtual interface multiply. For example, if you created the original IPv6 egress ACL with one rule, the ACL is programmed as 4 rules in TCAM for the FastIron 08.0.92 configuration; that is, 1 IPv6 ACL rule and 3 implicit rules. In the resulting configuration for the target release, the IPv6 ACL is applied at the VLAN level, and a total of 8 rules will be created in TCAM; that is, 2 ACL rules and 6 implicit rules.
Note: On ICX 7850 devices, there is no change in scale when you apply an egress ACL on a physical interface.