Displaying TCAM Information for ACLs
You can use different forms of the
show access-list tcam command to display information on the following items:
- IPv4 ACLs
- IPv6 ACLs
- MAC ACLs
- ACLs applied to the CPU
- ACLs applied to an interface or LAG
- ACLs applied to a stack unit
- ACLs applied to incoming traffic
- ACLs applied to outbound traffic
- Statistics on ACL rules stored in TCAM
- TCAM group types
Refer to the following examples for more information.
The following example provides TCAM information
for the IPv4 ACL named 136. The show access-list tcam acl-name command shows which ports have the
ACL programmed in TCAM, the type of ACL, which direction the ACL is applied, and
how
many rules, including the default rule, are programmed in TCAM for the ACL.
device(config-vlan-222)# show access-list tcam acl-name 136 Ingress: UnitId Feature SRule ERule Filters Contiguous RefCnt Bind If ------ ------- ----- ----- ------- ---------- ------ ------- 1 UACL-IPv4 1123 2125 1003 YES 1 e 1/1/18 2 UACL-IPv4 1123 2125 1003 YES 1 e 2/1/18
The following example provides detailed information for the same ACL. The detailed information includes ACL rules and associated ACL sequence numbers and ports.
device(config-vlan-222)# show access-list tcam acl-name 136 detail Ingress: UnitId Region Feature Filter ID Rule RefCnt Bind If ------ ------ ------- --------- ----- ------ ------- 1 0 UACL-IPv4 8 1123 1 e 1/1/18 1 0 UACL-IPv4 10 1124 1 e 1/1/18 1 0 UACL-IPv4 20 1125 1 e 1/1/18 1 0 UACL-IPv4 30 1126 1 e 1/1/18 1 0 UACL-IPv4 40 1127 1 e 1/1/18 1 0 UACL-IPv4 50 1128 1 e 1/1/18 1 0 UACL-IPv4 60 1129 1 e 1/1/18 1 0 UACL-IPv4 70 1130 1 e 1/1/18 1 0 UACL-IPv4 80 1131 1 e 1/1/18 ...
The following example displays the VLAN 333 configuration information on TCAM rules for the IPv6 ACL named vlan333-ipv6.
device(config-vlan-333)# show running-config vlan 333 vlan 333 by port tagged ethe 1/1/10 ethe 2/1/10 ethe 3/1/10 lag 25 interface ve 333 ipv6 access-group vlan333-ipv6 in <-- Applied VLAN shown in output mac access-group mac_acl in ip access-group vlan333-ipv4 in ip access-group frag deny ! ! device(config-vlan-333)# show access-list tcam acl-name vlan333-ipv6 Ingress: UnitId Feature SRule ERule Filters Contiguous RefCnt Bind If ------ ------- ----- ----- ------- ---------- ------ ------- 1 UACL-IPv6 641 786 146 YES 1 e 1/1/10 2 UACL-IPv6 1012 1157 146 YES 2 e 2/1/10 e 2/1/38 3 UACL-IPv6 1147 1292 146 YES 2 e 3/1/10 e 3/1/40
The following example shows detailed TCAM information for the same IPv6 ACL.
device(config-vlan-333)# show access-list tcam acl-name vlan333-ipv6 detail Ingress: UnitId Region Feature Filter ID Rule RefCnt Bind If ------ ------ ------- --------- ----- ------ ------- 1 0 UACL-IPv6 1 641 1 e 1/1/10 1 0 UACL-IPv6 2 642 1 e 1/1/10 1 0 UACL-IPv6 3 643 1 e 1/1/10 1 0 UACL-IPv6 6 644 1 e 1/1/10 1 0 UACL-IPv6 12 645 1 e 1/1/10 1 0 UACL-IPv6 13 646 1 e 1/1/10 1 0 UACL-IPv6 14 647 1 e 1/1/10
The following example breaks out TCAM rule information for a MAC ACL found in the running configuration for VLAN 333.
device(config-vlan-333)# show access-list tcam acl-name mac_acl Ingress: UnitId Feature SRule ERule Filters Contiguous RefCnt Bind If ------ ------- ----- ----- ------- ---------- ------ ------- 1 UACL-MAC 1119 1129 11 YES 1 e 1/1/10 2 UACL-MAC 1490 1500 11 YES 2 e 2/1/10 e 2/1/38 3 UACL-MAC 1625 1635 11 YES 2 e 3/1/10 e 3/1/40
device(config-vlan-333)# show access-list tcam acl-name mac_acl detail Ingress: UnitId Region Feature Filter ID Rule RefCnt Bind If ------ ------ ------- --------- ----- ------ ------- 1 0 UACL-MAC 10 1119 1 e 1/1/10 1 0 UACL-MAC 20 1120 1 e 1/1/10 1 0 UACL-MAC 30 1121 1 e 1/1/10 1 0 UACL-MAC 40 1122 1 e 1/1/10 1 0 UACL-MAC 50 1123 1 e 1/1/10 1 0 UACL-MAC 60 1124 1 e 1/1/10 1 0 UACL-MAC 70 1125 1 e 1/1/10 1 0 UACL-MAC 80 1126 1 e 1/1/10 1 0 UACL-MAC 90 1127 1 e 1/1/10 1 0 UACL-MAC 100 1128 1 e 1/1/10 1 0 UACL-MAC 65001 1129 1 e 1/1/10 2 0 UACL-MAC 10 1490 2 e 2/1/10 e 2/1/38
The following example displays TCAM usage for a specified stack unit. Information includes available TCAM space for IPv4, IPv6, and MAC ACLs. For a dual-PP device, the command output includes information on the region (0 or 1).
device# show access-list tcam usage unit 4 UnitId Region Group Id Direction Type : Allocated Total Free ------ ------ -------- --------- ---- : --------- ----- ---- 4 0 1 Pre-Ingres L2_IPv4 Filters : 1 512 511 4 0 2 Pre-Ingres VCAP_MISC : 0 1024 1024 4 0 3 Ingress IPv4 Filters : 9 2816 2807 4 0 4 Ingress IPv6 Filters : 0 1408 1408 4 0 5 Ingress L2 Filters : 30 2816 2786 4 0 6 Ingress ICAP All Combo : 51 768 717 4 0 7 Ingress IPSec Filters : 0 1408 1408 4 0 8 Egress IPv4 Filters : 0 256 256 4 0 9 Egress IPv6 Filters : 0 256 256 4 0 10 Egress L2 Filters : 3 256 253 4 1 1 Pre-Ingres L2_IPv4 Filters : 1 512 511 4 1 2 Pre-Ingres VCAP_MISC : 0 1024 1024 4 1 3 Ingress IPv4 Filters : 1031 2816 1785 4 1 4 Ingress IPv6 Filters : 7 896 889 4 1 6 Ingress ICAP All Combo : 51 512 461 4 1 7 Ingress IPSec Filters : 0 896 896 4 1 8 Egress IPv4 Filters : 4 256 252 4 1 9 Egress IPv6 Filters : 247 256 9 4 1 10 Egress L2 Filters : 3 256 253
The following example displays TCAM information for a specified interface. Use this command to verify ACLs applied on an interface and how many filters are programmed in TCAM for each ACL.
device# show access-list tcam interface ethernet 4/1/10 Ingress: UnitId AclName Feature SRule ERule Filters Contiguous Merged Acl ------ ------- ------- ----- ----- ------- ---------- --------- 4 STK_ZTP_0403 ZTP 36 36 1 YES 4 STK_IPC_0401 STK_HIGIG 5 5 1 YES 4 123 UACL-IPv4 84 104 21 YES 4 mac_acl UACL-MAC 105 115 11 YES Egress: UnitId AclName Feature SRule ERule Filters Contiguous Merged Acl ------ ------- ------- ----- ----- ------- ---------- --------- 4 140 UACL-IPv4 128 129 2 YES 4 egress UACL-IPv6 118 127 10 YES
The following example displays more detailed information for the same interface, including all rules and filters (by sequence number) for each ACL bound to the interface.
device# show access-list tcam interface ethernet 4/1/10 detail Ingress: UnitId Region AclName Feature Filter Id Rule ------ ------ ------- ------- --------- ----- 4 1 STK_ZTP_0403 ZTP 1 36 4 1 STK_IPC_0401 STK_HIGIG 1 5 4 1 123 UACL-IPv4 10 84 4 1 123 UACL-IPv4 20 85 4 1 123 UACL-IPv4 30 86 4 1 123 UACL-IPv4 40 87 4 1 123 UACL-IPv4 50 88 ...
The following example displays TCAM information for a specified LAG interface.
device# show access-list tcam interface lag 8060 Ingress: UnitId AclName Feature SRule ERule Filters Contiguous Merged Acl ------ ------- ------- ----- ----- ------- ---------- --------- 2 qos_dscp_34 QOS-DSCP/PCP 909 909 1 YES 3 qos_dscp_34 QOS-DSCP/PCP 907 907 1 YES Egress: UnitId AclName Feature SRule ERule Filters Contiguous Merged Acl ------ ------- ------- ----- ----- ------- ---------- --------- 2 125 UACL-IPv4 1587 1822 236 YES 2 egress UACL-IPv6 1823 2026 204 YES 3 125 UACL-IPv4 1585 1820 236 YES 3 egress UACL-IPv6 1821 2024 204 YES
The following example displays detailed information for a specified LAG.
device# show access-list tcam interface lag 8060 detail Ingress: UnitId Region AclName Feature Filter Id Rule ------ ------ ------- ------- --------- ----- 2 0 qos_dscp_34 QOS-DSCP/PCP 10 909 3 0 qos_dscp_34 QOS-DSCP/PCP 10 907 Egress: UnitId Region AclName Feature Filter Id Rule ------ ------ ------- ------- --------- ----- 2 0 125 UACL-IPv4 2 1587 2 0 125 UACL-IPv4 110 1588 2 0 125 UACL-IPv4 120 1589
The following example displays TCAM information for ACLs applied in an outbound direction on unit 1. The command output shows all ACLs programmed in TCAM for the specified unit in the specified direction, including system default rules.
device# show access-list tcam egress unit 1 Egress: UnitId AclName Feature SRule ERule Filters Contiguous RefCnt Bind If ------ ------- ------- ----- ----- ------- ---------- ------ ------- 1 ECPU_PORTID_RULE CPU_RULES 84 85 2 YES 1 1 ECPU_CLASSID_RULE CPU_RULES 86 86 1 YES 1
The show access-list tcam
rule-statistics command is used to display hardware-level accounting
statistics. The output is displayed for a specific rule in a specific region on
a
specific unit.
device# show access-list tcam rule-statistics 3161 unit 1 region 0 Rule: 3161 Stat: 0
The show access-list tcam rule
command displays output for a specific rule programmed in TCAM. The command is
local to
each unit. The following example displays information on rule 3161 for region 0
of unit
1.
device# show access-list tcam rule 3161 unit 1 region 0
EID 0x00000c59: gid=0x3,
slice=0, slice_idx=0xc9, part =0 prio=0x1fe0216, flags=0x210602, Installed, Enabled
tcam: color_indep=1,
StageIngress
InPorts
DATA=0x0000000000000000000000000000000000000000000000000008000000000800
MASK=0x00000000000000000000000000000000000000000000000003fe000001ffffff
Stage
IpType
Offset0: 325 Width0: 4
DATA=0x00000000
MASK=0x0000000e
InterfaceClassL2
Offset0: 32 Width0: 12
DATA=0x0000000e
MASK=0x00000fff
action={act=CosQCpuNew, param0=31(0x1f), param1=0(0x00), param2=0(0x00), param3=0(0x00)}
action={act=SwitchToCpuCancel, param0=0(0x00), param1=0(0x00), param2=0(0x00), param3=0(0x00)}
action={act=DynamicHgTrunkCancel, param0=0(0x00), param1=0(0x00), param2=0(0x00), param3=0(0x00)}
action={act=Drop, param0=0(0x00), param1=0(0x00), param2=0(0x00), param3=0(0x00)}
policer=
statistics={stat id 3079 slice = 6 idx=0 entries=1}{Packets}{Bytes}
The following example displays TCAM information for the ACL cpu-ipv4 applied to outgoing traffic on the CPU of the active controller for the stack.
device(config-if-cpu-active)# show access-list tcam acl-name cpu-ipv4 Egress: UnitId Feature SRule ERule Filters Contiguous RefCnt Bind If ------ ------- ----- ----- ------- ---------- ------ ------- 1 UACL-IPv4 2218 2220 3 YES 1 2 UACL-IPv4 1250 1252 3 YES 1
The following example provides information for
the icap-all-combo
group type. The output includes the unit ID, ACL name, associated feature, start
and end
rule numbers, number of filters, filter contiguity status, reference count, and
the
bound interfaces.
device# show access-list tcam group icap-all-combo
UnitId AclName Feature SRule ERule Filters Contiguous RefCnt Bind If
----- ------- ------- ----- ----- ------- ---------- ------ -------
1 SFLOW_RULE SFLOW 262145 262145 1 YES 52 e 1/1/1 to 1/1/48
e 1/2/1 to 1/2/4
1 SYSTEM-L3-UDP-BC UDP_BC 262146 262150 5 YES 52 e 1/1/1 to 1/1/48
e 1/2/1 to 1/2/4
1 SYSTEM-L3-OSPFv2 OSPF 262151 262151 1 YES 52 e 1/1/1 to 1/1/48
e 1/2/1 to 1/2/4
1 SYSTEM-L3-OSPFv3 OSPF 262152 262152 1 YES 52 e 1/1/1 to 1/1/48
e 1/2/1 to 1/2/4
1 SYSTEM-L3-GRE GRE 262153 262153 1 YES 52 e 1/1/1 to 1/1/48
e 1/2/1 to 1/2/4
1 SYSTEM-L3-IPV6-RES-MC IPV6_RES_MC 262154 262154 1 YES 52 e 1/1/1 to 1/1/48
e 1/2/1 to 1/2/4
1 SYSTEM-DDOS-TCP-SYN-IPV4 DA_MGMT 262195 262195 1 YES 52 e 1/1/1 to 1/1/48
e 1/2/1 to 1/2/4
1 FLEXAUTH_802.1X_BPDU_RULE FLEXAUTH 262155 262155 1 YES 52 e 1/1/1 to 1/1/48
e 1/2/1 to 1/2/4
1 ICMP-ECHO-BC ICMP_BC 262196 262196 1 YES 52 e 1/1/1 to 1/1/48
e 1/2/1 to 1/2/4
1 SYSTEM-L3-VRRP VRRP 262156 262157 2 YES 52 e 1/1/1 to 1/1/48
e 1/2/1 to 1/2/4
1 SYSTEM-L3-ND ND 262158 262160 3 YES 52 e 1/1/1 to 1/1/48
e 1/2/1 to 1/2/4
1 SYS_DHCPV6_CLIENT DHCPV6_CLIENT262197 262197 1 YES 52 e 1/1/1 to 1/1/48
e 1/2/1 to 1/2/4