show access-list tcam

Displays where access control lists (ACLs) are programmed in the Ternary Content Addressable Memory (TCAM). This includes the ACL names, associated features, rule ranges, filter counts, and the interfaces to which the ACLs are bound.
Syntax
show access-list tcam acl-name name [ detail ]
show access-list tcam detail
show access-list tcam { egress [ unit id ] | ingress [ unit id ] } [ detail ]
show access-list tcam group group-type
show access-list tcam { interface ethernet unit/slot/port | interface lag id } [ detail ]
show access-list tcam rule start-rule [ end-rule ] unit unit/slot/port region region-id [detail ]
show access-list tcam rule-statistics id unit id region region-id [ detail ]
show access-list tcam usage unit id
Parameters
acl-name name
Displays TCAM information for the specified ACL.
detail
Displays detailed TCAM information.
egress
Displays information for egress (outgoing) TCAM rules on the specified unit.
unit id
Displays TCAM rules programmed on the specified unit, including default rules.
ingress
Displays information for ingress (incoming) TCAM rules on the specified unit.
group group-type
Displays detailed information about ACLs configured in a specific TCAM group type, including associated features, rule ranges, filter counts, and bound interfaces. The following group-type values are supported:
  • ecap-ipv4: Group type ECAP_IPv4_FILTERS
  • ecap-ipv6: Group type ECAP_IPv6_FILTERS
  • ecap-l2: Group type ECAP_L2_FILTERS
  • icap-all-combo: Group type ICAP_ALL_COMBO
  • icap-ipsec: Group type ICAP_IPSEC
  • icap-ipv4: Group type ICAP_IPv4_FILTERS
  • icap-ipv4-ipv6-tcpmss: Group type ICAP_IPV4_IPV6_TCPMSS
  • icap-ipv6: Group type ICAP_IPv6_FILTERS
  • icap-l2: Group type ICAP_L2_FILTERS
  • l2-stk: Group type L2_STK_FILTERS
  • vcap-l2-ipv4: Group type VCAP_L2_IPv4
  • vcap-misc: Group type VCAP_MISC
interface ethernet unit/slot/port
Displays TCAM information for the specified Ethernet interface.
interface lag id
Displays TCAM information for the specified Link Aggregation Group (LAG) interface.
rule-statistics id
Displays statistics for a specific rule programmed in TCAM by rule ID.
unit unit/slot/port
Displays TCAM rule information for a specific hardware interface identified by unit, slot, and port.
region region-id
Displays the region identifier within TCAM where the rule is programmed.
rule id
Displays detailed information for each rule programmed in TCAM.
start-rule
Displays information starting from this rule index in TCAM.
end-rule
Displays information up to this rule index in TCAM.
usage unit id
Displays TCAM usage statistics for the specified unit.
Modes

User EXEC mode

The show access-list tcam command displays the following information (depending on the command parameters used):

Output field Description
UnitId Identifies the unit ID.
AclName Name of the ACL.
Feature Feature associated with the ACL.
SRule Starting rule number.
ERule Ending rule number.
Filters Number of filters programmed in TCAM.
Contiguous Indicates if the rules are contiguous.
RefCnt Reference count.
Bind If Bound interface.
Region Region ID.
Filter ID Displays the filter ID associated with each rule programmed in TCAM.
Rule Rule number.
Merged Acl Indicates if the ACL is merged.
Direction Direction of the ACL (Pre-Ingress, Ingress, or Egress).
Type Type of the ACL.
Allocated Number of allocated entries.
Total Total number of entries.
Free Number of free entries.
EID Entry ID.
gid Group Identifier.
slice Slice number.
slice_idx Slice index.
part Part number.
prio Priority
flags Flags associated with the rule.
Installed Indicates if the rule is installed.
Enabled Indicates if the rule is enabled.
tcam TCAM details.
Stage Stage of the rule (Pre-Ingress, Ingress, or Egress).
InPorts Input ports.
MASK Mask associated with the rule.
action Actions associated with the rule.
policer Policer details.
statistics Statistics associated with the rule.
Examples

The following example displays information for the icap-all-combo group type. The output includes details such as unit ID, ACL name, associated feature, rule range, number of filters, filter contiguity, reference count, and bound interfaces.

device# show access-list tcam group icap-all-combo

UnitId AclName                Feature     SRule  ERule Filters Contiguous RefCnt Bind If
----- -------                 -------     -----  ----- ------- ---------- ------ -------
1    SFLOW_RULE               SFLOW       262145 262145 1       YES        52   e 1/1/1 to 1/1/48
                                                                                e 1/2/1 to 1/2/4
1    SYSTEM-L3-UDP-BC         UDP_BC      262146 262150 5       YES        52   e 1/1/1 to 1/1/48
                                                                                e 1/2/1 to 1/2/4
1    SYSTEM-L3-OSPFv2         OSPF        262151 262151 1       YES        52   e 1/1/1 to 1/1/48
                                                                                e 1/2/1 to 1/2/4
1    SYSTEM-L3-OSPFv3         OSPF        262152 262152 1       YES        52   e 1/1/1 to 1/1/48
                                                                                e 1/2/1 to 1/2/4
1    SYSTEM-L3-GRE            GRE         262153 262153 1       YES        52   e 1/1/1 to 1/1/48
                                                                                e 1/2/1 to 1/2/4
1    SYSTEM-L3-IPV6-RES-MC    IPV6_RES_MC 262154 262154 1       YES        52   e 1/1/1 to 1/1/48
                                                                                e 1/2/1 to 1/2/4
1    SYSTEM-DDOS-TCP-SYN-IPV4 DA_MGMT     262195 262195 1       YES        52   e 1/1/1 to 1/1/48
                                                                                e 1/2/1 to 1/2/4
1    FLEXAUTH_802.1X_BPDU_RULE FLEXAUTH   262155 262155 1       YES        52   e 1/1/1 to 1/1/48
                                                                                e 1/2/1 to 1/2/4
1    ICMP-ECHO-BC             ICMP_BC     262196 262196 1       YES        52   e 1/1/1 to 1/1/48
                                                                                e 1/2/1 to 1/2/4
1    SYSTEM-L3-VRRP           VRRP        262156 262157 2       YES        52   e 1/1/1 to 1/1/48
                                                                                e 1/2/1 to 1/2/4
1    SYSTEM-L3-ND             ND          262158 262160 3       YES        52   e 1/1/1 to 1/1/48
                                                                                e 1/2/1 to 1/2/4
1    SYS_DHCPV6_CLIENT       DHCPV6_CLIENT262197 262197 1       YES        52   e 1/1/1 to 1/1/48
                                                                                e 1/2/1 to 1/2/4

The following example displays the ports that have ACL 136 programmed in TCAM for a VLAN.

device(config-vlan-222)# show access-list tcam acl-name 136
Ingress:
UnitId Feature   SRule ERule Filters Contiguous RefCnt Bind If
------ -------   ----- ----- ------- ---------- ------ -------
1      UACL-IPv4 1123  2125  1003    YES        1      e 1/1/18
2      UACL-IPv4 1123  2125  1003    YES        1      e 2/1/18

The following example displays detailed information for the ports that have ACL 136 programmed in TCAM for a VLAN.

device(config-vlan-222)# show access-list tcam acl-name 136 detail
Ingress:
UnitId Region Feature   Filter ID Rule  RefCnt Bind If
------ ------ -------   --------- ----- ------ -------
1      0      UACL-IPv4  8        1123  1      e 1/1/18
1      0      UACL-IPv4 10        1124  1      e 1/1/18
1      0      UACL-IPv4 20        1125  1      e 1/1/18
1      0      UACL-IPv4 30        1126  1      e 1/1/18
1      0      UACL-IPv4 40        1127  1      e 1/1/18
1      0      UACL-IPv4 50        1128  1      e 1/1/18
1      0      UACL-IPv4 60        1129  1      e 1/1/18
1      0      UACL-IPv4 70        1130  1      e 1/1/18
1      0      UACL-IPv4 80        1131  1      e 1/1/18

The following example displays allocated, total, and free entries for various ACL types on stack unit 1.

device# show access-list tcam usage unit 1

UnitId Region Group Id   Direction       Type                : Allocated  Total   Free
------ ------ --------   ---------       ----                : ---------  -----   ----
1      0      1          Pre-Ingres      L2_IPv4 Filters     : 1          1536    1535
1      0      2          Pre-Ingres      VCAP_MISC           : 0          1536    1536
1      0      3/4        Ingress         IPv4/v6 Filters     : 8/0        2048    2040
1      0      5          Ingress         L2 Filters          : 30         2048    2018
1      0      6          Ingress         ICAP All Combo      : 58         2048    1990
1      0      7          Egress          IPv4 Filters        : 1          256     255
1      0      8          Egress          IPv6 Filters        : 1          256     255
1      0      9          Egress          L2 Filters          : 5          256     251

The following example displays TCAM information for all ACLs applied for a specified Ethernet interface.

device# show access-list tcam interface ethernet 4/1/10
Ingress:
UnitId AclName      Feature    SRule ERule  Filters Contiguous Merged Acl
------ -------      -------    ----- -----  ------- ---------- ---------
4      STK_ZTP_0403 ZTP         36    36    1       YES
4      STK_IPC_0401 STK_HIGIG    5     5    1       YES
4      123          UACL-IPv4   84   104   21       YES
4      mac_acl      UACL-MAC   105   115   11       YES

Egress:
UnitId AclName      Feature    SRule ERule Filters Contiguous Merged Acl
------ -------      -------    ----- ----- ------- ---------- ---------
4      140          UACL-IPv4  128   129    2      YES
4      egress       UACL-IPv6  118   127   10      YES

The following example displays detailed TCAM information for all ACLs applied for a specified Ethernet interface.

device# show access-list tcam interface ethernet 4/1/10 detail
Ingress:
UnitId Region AclName        Feature     Filter Id Rule
------ ------ -------        -------     --------- -----
4      1      STK_ZTP_0403   ZTP         1         36
4      1      STK_IPC_0401   STK_HIGIG   1          5
4      1      123            UACL-IPv4  10         84
4      1      123            UACL-IPv4  20         85
4      1      123            UACL-IPv4  30         86
4      1      123            UACL-IPv4  40         87
4      1      123            UACL-IPv4  50         88

The following example displays TCAM information for all ACLs applied for a specified LAG interface.

device# show access-list tcam interface lag 8060
Ingress:
UnitId AclName     Feature       SRule  ERule Filters Contiguous Merged Acl
------ -------     -------       -----  ----- ------- ---------- ---------
2      qos_dscp_34 QOS-DSCP/PCP   909    909  1       YES
3      qos_dscp_34 QOS-DSCP/PCP   907    907  1       YES

Egress:
UnitId AclName     Feature       SRule  ERule Filters Contiguous Merged Acl
------ -------     -------       -----  ----- ------- ---------- ---------
2      125         UACL-IPv4      1587   1822 236     YES
2      egress      UACL-IPv6      1823   2026 204     YES
3      125         UACL-IPv4      1585   1820 236     YES
3      egress      UACL-IPv6      1821   2024 204     YES

The following example displays detailed TCAM information for all ACLs applied for a LAG interface.

device# show access-list tcam interface lag 8060 detail
Ingress:
UnitId Region AclName     Feature      Filter Id Rule
------ ------ -------     -------      --------- -----
2      0      qos_dscp_34 QOS-DSCP/PCP 10        909
3      0      qos_dscp_34 QOS-DSCP/PCP 10        907

Egress:
UnitId Region AclName     Feature      Filter Id Rule
------ ------ -------     -------      --------- -----
2      0      125         UACL-IPv4      2       1587
2      0      125         UACL-IPv4    110       1588
2      0      125         UACL-IPv4    120       1589

The following example displays TCAM information for ACLs applied in an outbound direction on unit 1. The output shows all ACLs programmed in TCAM for the specified unit in the specified direction, including system default rules.

device# show access-list tcam egress unit 1
Egress:
UnitId AclName           Feature    SRule ERule Filters Contiguous RefCnt Bind If
------ -------           -------    ----- ----- ------- ---------- ------ -------
1      ECPU_PORTID_RULE  CPU_RULES   84    85   2       YES        1
1      ECPU_CLASSID_RULE CPU_RULES   86    86   1       YES        1

The following example displays hardware-level accounting statistics for a specific rule in a specific region on a specific unit.

device# show access-list tcam rule-statistics 3161 unit 1 region 0
Rule: 3161 Stat: 0

The following example displays output for rule 3161 programmed in TCAM. Information is displayed for rule 3161 in region 0 on unit 1.

device# show access-list tcam rule 3161 unit 1 region 0
EID 0x00000c59: gid=0x3,
slice=0, slice_idx=0xc9, part =0 prio=0x1fe0216, flags=0x210602, Installed, Enabled
tcam: color_indep=1,
StageIngress
InPorts
DATA=0x0000000000000000000000000000000000000000000000000008000000000800
MASK=0x00000000000000000000000000000000000000000000000003fe000001ffffff
Stage
IpType
Offset0: 325 Width0: 4
DATA=0x00000000
MASK=0x0000000e
InterfaceClassL2
Offset0: 32 Width0: 12
DATA=0x0000000e
MASK=0x00000fff
action={act=CosQCpuNew, param0=31(0x1f), param1=0(0x00), param2=0(0x00), param3=0(0x00)}
action={act=SwitchToCpuCancel, param0=0(0x00), param1=0(0x00), param2=0(0x00), param3=0(0x00)}
action={act=DynamicHgTrunkCancel, param0=0(0x00), param1=0(0x00), param2=0(0x00), param3=0(0x00)}
action={act=Drop, param0=0(0x00), param1=0(0x00), param2=0(0x00), param3=0(0x00)}
policer=
statistics={stat id 3079 slice = 6 idx=0 entries=1}{Packets}{Bytes}

The following example displays TCAM information for ACL cpu-ipv4 applied to outgoing traffic on the CPU of the active controller for the stack.

device# show access-list tcam acl-name cpu-ipv4
Egress:
UnitId Feature   SRule ERule Filters Contiguous RefCnt Bind If
------ -------   ----- ----- ------- ---------- ------ -------
1      UACL-IPv4 2218  2220  3       YES        1
2      UACL-IPv4 1250  1252  3       YES        1
History
Release version Command history
08.0.95 This command was introduced.
10.0.10c The group keyword was added.
10.0.10g_cd1 The show access-list tcam group option is updated so that group-type is specified instead of group-id.