show access-list tcam

Displays where port ACLs are programmed in the ternary content-addressable memory (TCAM), how many rules, including the default rule, are configured for each ACL, and which direction each ACL is applied.
Syntax
show access-list tcam { acl-name name } [ detail ]
show access-list tcam [ acl-name FILTER_PTP_PKT ]
show access-list tcam { usage unit id }
show access-list tcam { group group id }
show access-list tcam { interface ethernet unit/slot/port | Interface lag id } [ detail ]
show access-list tcam { ingress unit id| egress unit id } [ detail ]
show access-list tcam { rule statistics id unit unit/slot/port region region-id } [ detail ]
show access-list tcam { rule id unit unit/slot/port region region-id } [detail ]
Parameters
acl-name name
Displays TCAM information for the designated ACL.
usage unit id
Displays information on TCAM usage for a specific unit.
group group id
Displays information on ACL installed for a specific TCAM group (value is greater than show acces-list tcam usage's Group ID).
interface ethernet unit/slot/port
Displays TCAM information for a specified Ethernet interface.
interface lag id
Displays TCAM information for a specified LAG interface.
ingress unit id
Displays a list of rules programmed on a particular ingress unit, including default rules.
egress unit id
Displays a list of rules programmed on a particular egress unit, including default rules.
rule statistics id unit unit/slot/port region region-id
Displays accounting information for hardware-level statistics.
rule id unit unit/slot/port region region-id
Displays detailed output for each rule programmed in TCAM. Output is local to each unit.
detail
Displays all rules for a particular ACL with sequence number and port details.
FILTER_PTP_PKT
Displays all ACL rules for handling PTP packets.
Modes

User EXEC mode

Examples

The following is an example of the show access-list tcam group command usage:

Device Router#show access-list tcam group 5
  UnitId AclName                                Feature       SRule  ERule  Filters Contiguous RefCnt Bind If                                    
  ------ -------                                -------       -----  -----  ------- ---------- ------ -------                                    
  1      SFLOW_RULE                             SFLOW         36     36     1       YES        25     e 1/1/1 to 1/1/24 e 1/2/2                  
  1      SYS_CPU_VLAN_BPDU                      VLAN          37     37     1       YES        1                                                 
  1      SYS_PVST                               XSTP          38     38     1       YES        25     e 1/1/1 to 1/1/24 e 1/2/2                  
  1      SYS_PROTO_REPRIO                       L2_PROTO      39     40     2       YES        25     e 1/1/1 to 1/1/24 e 1/2/2                  
  1      SYS_VXVLAN_CROSS_CONNECT_VNI           VXLAN         94     98     5       YES        25     e 1/1/1 to 1/1/24 e 1/2/2                  
  1      SYSTEM-L3-UDP-BC                       UDP_BC        41     45     5       YES        25     e 1/1/1 to 1/1/24 e 1/2/2                  
  1      MCAST_ACL_RULES_IGMP                   IGMP          46     46     1       YES        25     e 1/1/1 to 1/1/24 e 1/2/2                  
  1      MCAST_ACL_RULES_DNS                    IGMP          47     47     1       YES        25     e 1/1/1 to 1/1/24 e 1/2/2                  
  1      MCAST_ACL_RULES_RES_MC_V4              RES_MC_V4     48     48     1       YES        25     e 1/1/1 to 1/1/24 e 1/2/2                  
  1      MCAST_ACL_RULES_MLD_V1                 MLD           49     49     2       YES        25     e 1/1/1 to 1/1/24 e 1/2/2                  
  1      MCAST_ACL_RULES_MLD_V2                 MLD           52     52     1       YES        25     e 1/1/1 to 1/1/24 e 1/2/2                  
  1      MCAST_ACL_RULES_PIM_V6                 PIMV6         53     53     1       YES        25     e 1/1/1 to 1/1/24 e 1/2/2                  
  1      L3MCAST_ACL_RULES_PIM_REG              PIM_REG       54     54     1       YES        25     e 1/1/1 to 1/1/24 e 1/2/2                  
  1      SYSTEM-L3-OSPFv2                       OSPF          55     55     1       YES        25     e 1/1/1 to 1/1/24 e 1/2/2                  
  1      SYSTEM-L3-OSPFv3                       OSPF          56     56     1       YES        25     e 1/1/1 to 1/1/24 e 1/2/2                  
  1      SYSTEM-L3-GRE                          GRE           57     57     1       YES        25     e 1/1/1 to 1/1/24 e 1/2/2                  
  1      SYSTEM-L3-TCP-MSS-IPV6                 TCP_MSS       58     58     1       YES        25     e 1/1/1 to 1/1/24 e 1/2/2                  
  1      SYSTEM-L3-TCP-MSS-IPV4                 TCP_MSS       59     59     1       YES        25     e 1/1/1 to 1/1/24 e 1/2/2                  
  1      SYSTEM-L3-TCP-MSS-EGRESS               TCP_MSS       60     60     1       YES        25     e 1/1/1 to 1/1/24 e 1/2/2                  
  1      SYSTEM-L3-IPV6-RES-MC                  IPV6_RES_MC   61     61     1       YES        25     e 1/1/1 to 1/1/24 e 1/2/2                  
  1      SYSTEM-DDOS-TCP-SYN-IPV4               DA_MGMT       117    117    1       YES        25     e 1/1/1 to 1/1/24 e 1/2/2                  
  1      FLEXAUTH_802.1X_BPDU_RULE              FLEXAUTH      62     62     1       YES        25     e 1/1/1 to 1/1/24 e 1/2/2                  
  1      SYSTEM-L3-VRRP                         VRRP          63     64     2       YES        25     e 1/1/1 to 1/1/24 e 1/2/2

The following example provides TCAM information for ACL 136 on VLAN 222. The show access-list tcam acl-name command shows which ports have the ACL programmed in TCAM, the type of ACL, which direction the ACL is applied, and how many rules, including the default rule, are programmed in TCAM for the ACL.

device(config-vlan-222)# show access-list tcam acl-name 136 (ACL NAME)
Ingress
UnitId Feature   SRule ERule Filters Contiguous RefCnt Bind If
------ -------   ----- ----- ------- ---------- ------ -------
1      UACL-IPv4 1123  2125  1003    YES        1      e 1/1/18
2      UACL-IPv4 1123  2125  1003    YES        1      e 2/1/18

The following example provides detailed information for the same ACL. The detailed information includes ACL rules and associated ACL sequence numbers and ports.

device(config-vlan-222)# show access-list tcam acl-name 136 detail
Ingress:
UnitId Region Feature   Filter ID Rule  RefCnt Bind If
------ ------ -------   --------- ----- ------ -------
1      0      UACL-IPv4  8        1123  1      e 1/1/18
1      0      UACL-IPv4 10        1124  1      e 1/1/18
1      0      UACL-IPv4 20        1125  1      e 1/1/18
1      0      UACL-IPv4 30        1126  1      e 1/1/18
1      0      UACL-IPv4 40        1127  1      e 1/1/18
1      0      UACL-IPv4 50        1128  1      e 1/1/18
1      0      UACL-IPv4 60        1129  1      e 1/1/18
1      0      UACL-IPv4 70        1130  1      e 1/1/18
1      0      UACL-IPv4 80        1131  1      e 1/1/18

The following example displays TCAM usage for stack unit 1. This output is available on ICX 7550 and ICX 7850 devices.

ICX8200-48P Router#sh acc tcam usage un 1
UnitId Region Group Id   Direction       Type                : Allocated  Total   Free
------ ------ --------   ---------       ----                : ---------  -----   ----
1      0      1          Pre-Ingres      L2_IPv4 FIlters     : 1          1536    1535
1      0      2          Pre-Ingres      VCAP_MISC           : 0          1536    1536
1      0      3/4        Ingress         IPv4/v6 Filters     : 8/0        2048    2040
1      0      5          Ingress         L2 Filters          : 30         2048    2018
1      0      6          Ingress         ICAP All Combo      : 58         2048    1990
1      0      7          Egress          IPv4 Filters        : 1          256     255
1      0      8          Egress          IPv6 Filters        : 1          256     255
1      0      9          Egress          L2 Filters          : 5          256     251

The following example displays TCAM usage for stack unit 1 on an ICX 8200 device.

ICX8200-48P Router#
UnitId Region Group Id   Direction       Type                : Allocated  Total      Free
------ ------ --------   ---------       ----                : ---------  -----      ----
1      0      0          Pre-Ingres      VCAP_MISC           : 1          129        128
1      0      1          Ingress         IPv4 Filters        : 6          1024       1018
1      0      2          Ingress         IPv6 Filters        : 1          512        511
1      0      3          Ingress         L2 Filters          : 31         512        481
1      0      4          Ingress         ICAP All Combo      : 53         256        203
1      0      5          Egress          IPv4 Filters        : 1          128        127
1      0      6          Egress          IPv6 Filters        : 1          128        127
1      0      7          Egress          L2 Filters          : 6          256        250

The following example displays TCAM information for a specified interface. Use this command to verify ACLs applied on an interface and how many filters are programmed in TCAM for each ACL.

device# show access-list tcam interface ethernet 4/1/10
Ingress:
UnitId AclName      Feature    SRule ERule  Filters Contiguous Merged Acl
------ -------      -------    ----- -----  ------- ---------- ---------
4      STK_ZTP_0403 ZTP         36    36    1       YES
4      STK_IPC_0401 STK_HIGIG    5     5    1       YES
4      123          UACL-IPv4   84   104   21       YES
4      mac_acl      UACL-MAC   105   115   11       YES

Egress:
UnitId AclName      Feature    SRule ERule Filters Contiguous Merged Acl
------ -------      -------    ----- ----- ------- ---------- ---------
4      140          UACL-IPv4  128   129    2      YES
4      egress       UACL-IPv6  118   127   10      YES

The following example displays more detailed information for the same interface, including all rules and filters (by sequence number) for each ACL bound to the interface.

device# show access-list tcam interface ethernet 4/1/10 detail
Ingress:
UnitId Region AclName        Feature     Filter Id Rule
------ ------ -------        -------     --------- -----
4      1      STK_ZTP_0403   ZTP         1         36
4      1      STK_IPC_0401   STK_HIGIG   1          5
4      1      123            UACL-IPv4  10         84
4      1      123            UACL-IPv4  20         85
4      1      123            UACL-IPv4  30         86
4      1      123            UACL-IPv4  40         87
4      1      123            UACL-IPv4  50         88

The following example displays TCAM information for a specified LAG interface.

device# show access-list tcam interface lag 8060
Ingress:
UnitId AclName     Feature       SRule  ERule Filters Contiguous Merged Acl
------ -------     -------       -----  ----- ------- ---------- ---------
2      qos_dscp_34 QOS-DSCP/PCP   909    909  1       YES
3      qos_dscp_34 QOS-DSCP/PCP   907    907  1       YES

Egress:
UnitId AclName     Feature       SRule  ERule Filters Contiguous Merged Acl
------ -------     -------       -----  ----- ------- ---------- ---------
2      125         UACL-IPv4      1587   1822 236     YES
2      egress      UACL-IPv6      1823   2026 204     YES
3      125         UACL-IPv4      1585   1820 236     YES
3      egress      UACL-IPv6      1821   2024 204     YES

The following example displays detailed information for the same LAG.

device# show access-list tcam interface lag 8060 detail
Ingress:
UnitId Region AclName     Feature      Filter Id Rule
------ ------ -------     -------      --------- -----
2      0      qos_dscp_34 QOS-DSCP/PCP 10        909
3      0      qos_dscp_34 QOS-DSCP/PCP 10        907

Egress:
UnitId Region AclName     Feature      Filter Id Rule
------ ------ -------     -------      --------- -----
2      0      125         UACL-IPv4      2       1587
2      0      125         UACL-IPv4    110       1588
2      0      125         UACL-IPv4    120       1589

The following example displays a list of all ACLs and associated rules, including default rules, programmed on unit 1 in an inbound direction.

device# show access-list tcam ingress unit 1

Ingress:
UnitId AclName                         Feature      SRule ERule    Filters Contiguous RefCnt Bind If
------ -------                         -------      ----- -----    ------- ---------- ------ -------
1 SFLOW_RULE                           SFLOW        34       34       1    YES        30     e 1/1/1 to 1/1/24 e 1/2/2 e 1/2/4 to 1/2/8
1 INGRESS_CPU_RULE                     CPU_RULES     5        5       1    YES        33     e 1/1/1 to 1/1/24 e 1/2/1 to 1/2/8
1 MANAGEMENT                           UACL-IPv4  3165     3356     192    YES         1     e 1/1/2
1 SYS_MGMT_VLAN                        VLAN          6        6       1    YES        30     e 1/1/1 to 1/1/24 e 1/2/2 e 1/2/4 to 1/2/8
1 SYSTEM-L3-UDP-BC                     UDP_BC       35       35       1    YES        30     e 1/1/1 to 1/1/24 e 1/2/2 e 1/2/4 to 1/2/8
1 SPX_ZTP_0402                         SPX_IPC_MAC  36       36       1    YES        30     e 1/1/1 to 1/1/24 e 1/2/2 e 1/2/4 to 1/2/8
1 STK_ZTP_0403                         ZTP          37       37       1    YES        30     e 1/1/1 to 1/1/24 e 1/2/2 e 1/2/4 to 1/2/8
1 STK_IPC_0401                         STK_HIGIG     7        7       1    YES        30     e 1/1/1 to 1/1/24 e 1/2/2 e 1/2/4 to 1/2/8
1 MCAST_ACL_RULES_IGMP                 IGMP         38       38       1    YES        30     e 1/1/1 to 1/1/24 e 1/2/2 e 1/2/4 to 1/2/8
1 MCAST_ACL_RULES_PIM_V4               PIMV4        39       39       1    YES        30     e 1/1/1 to 1/1/24 e 1/2/2 e 1/2/4 to 1/2/8
1 MCAST_ACL_RULES_RES_MC_V4            RES_MC_V4    40       40       1    YES        30     e 1/1/1 to 1/1/24 e 1/2/2 e 1/2/4 to 1/2/8
1 MCAST_ACL_RULES_SC_SP_MLD_V1         MLD          41       41       2    YES        30     e 1/1/1 to 1/1/24 e 1/2/2 e 1/2/4 to 1/2/8
1 MCAST_ACL_RULES_SC_SP_MLD_V2         MLD          44       44       1    YES        30     e 1/1/1 to 1/1/24 e 1/2/2 e 1/2/4 to 1/2/8
1 MCAST_ACL_RULES_SC_SP_PIM_V6         PIMV6        45       45       1    YES        30     e 1/1/1 to 1/1/24 e 1/2/2 e 1/2/4 to 1/2/8
1 SYS_CPU_VLAN_BPDU                    VLAN         46       46       1    YES         1
1 SYS_PVST                             XSTP         47       47       1    YES        30     e 1/1/1 to 1/1/24 e 1/2/2 e 1/2/4 to 1/2/8
1 SYS_MRP                              MRP           8        8       1    YES        30     e 1/1/1 to 1/1/24 e 1/2/2 e 1/2/4 to 1/2/8
1 SYS_UDLD                             UDLD          9        9       1    YES        30     e 1/1/1 to 1/1/24 e 1/2/2 e 1/2/4 to 1/2/8
1 SYS_EOAM_LOOPBACK                    EOAM         48       48       1    YES        30     e 1/1/1 to 1/1/24 e 1/2/2 e 1/2/4 to 1/2/8
1 SYS_SMAC_SUP                         FDB          10       10       1    YES        30     e 1/1/1 to 1/1/24 e 1/2/2 e 1/2/4 to 1/2/8
1 SYSTEM-L3-IPV6-RES-MC                IPV6_RES_MC  49       49       1    YES        30     e 1/1/1 to 1/1/24 e 1/2/2 e 1/2/4 to 1/2/8
1 SYSTEM-L3-IRDP                       IRDP          1        1       1    YES        30     e 1/1/1 to 1/1/24 e 1/2/2 e 1/2/4 to 1/2/8
1 SYSTEM-L3-ARP-PRIORITY               ARP          11       11       1    YES        30     e 1/1/1 to 1/1/24 e 1/2/2 e 1/2/4 to 1/2/8
1 FLEXAUTH_802.1X_BPDU_RULE_UNIT_1     FLEXAUTH     50       50       1    YES        30     e 1/1/1 to 1/1/24 e 1/2/2 e 1/2/4 to 1/2/8
1 SYS_PROTO_REPRIO                     L2_PROTO     51       52       2    YES        30     e 1/1/1 to 1/1/24 e 1/2/2 e 1/2/4 to 1/2/8
1 L2MCAST-ACL-RULES-SPATHA-SICA-UMC-V6 MC_UMC       53       55       3    YES        30     e 1/1/1 to 1/1/24 e 1/2/2 e 1/2/4 to 1/2/8
1 SYSTEM-L3-ND                         ND           56       58       3    YES        30     e 1/1/1 to 1/1/24 e 1/2/2 e 1/2/4 to 1/2/8
1 scale22                              UACL-IPv6  2357     3160     804    YES         2     e 1/1/11 e 1/2/2
1 131                                  UACL-IPv4  3161     3164       4    YES         2     e 1/1/11 e 1/2/2

The following example displays TCAM information for ACLs applied in an outbound direction on unit 1. The command shows all ACLs programmed in TCAM for the specified unit in the specified direction, including system default rules.

device# show access-list tcam egress unit 1
Egress:
UnitId AclName           Feature    SRule ERule Filters Contiguous RefCnt Bind If
------ -------           -------    ----- ----- ------- ---------- ------ -------
1      ECPU_PORTID_RULE  CPU_RULES   84    85   2       YES        1
1      ECPU_CLASSID_RULE CPU_RULES   86    86   1       YES        1

The show access-list tcam rule-statistics command is used to fetch hardware-level accounting statistics. The output is displayed for a specific rule in a specific region on a specific unit.

device# show access-list tcam rule-statistics 3161 unit 1 region 0
Rule: 3161 Stat: 0

The show access-list tcam rule command displays detailed output for each rule programmed in TCAM. The command is local to each unit. The following example displays information on rules for region 0 of unit 1.

device# show access-list tcam rule 3161 unit 1 region 0
EID 0x00000c59: gid=0x3,
slice=0, slice_idx=0xc9, part =0 prio=0x1fe0216, flags=0x210602, Installed, Enabled
tcam: color_indep=1,
StageIngress
InPorts
DATA=0x0000000000000000000000000000000000000000000000000008000000000800
MASK=0x00000000000000000000000000000000000000000000000003fe000001ffffff
Stage
IpType
Offset0: 325 Width0: 4
DATA=0x00000000
MASK=0x0000000e
InterfaceClassL2
Offset0: 32 Width0: 12
DATA=0x0000000e
MASK=0x00000fff
action={act=CosQCpuNew, param0=31(0x1f), param1=0(0x00), param2=0(0x00), param3=0(0x00)}
action={act=SwitchToCpuCancel, param0=0(0x00), param1=0(0x00), param2=0(0x00), param3=0(0x00)}
action={act=DynamicHgTrunkCancel, param0=0(0x00), param1=0(0x00), param2=0(0x00), param3=0(0x00)}
action={act=Drop, param0=0(0x00), param1=0(0x00), param2=0(0x00), param3=0(0x00)}
policer=
statistics={stat id 3079 slice = 6 idx=0 entries=1}{Packets}{Bytes}

The following example displays TCAM information for the ACL cpu-ipv4 applied to incoming traffic on the CPU of the active controller for the stack.

device# configure terminal
device(config)# interface cpu active
device(config-if-cpu-active)# ip access-group cpu-ipv4 in

device(config-if-cpu-active)# show access-list tcam acl-name cpu-ipv4
Egress:
UnitId Feature   SRule ERule Filters Contiguous RefCnt Bind If
------ -------   ----- ----- ------- ---------- ------ -------
1      UACL-IPv4 2218  2220  3       YES        1
2      UACL-IPv4 1250  1252  3       YES        1

The show access-list tcam acl-name FILTER_PTP_PKT command displays all the ACL rules created for handling PTP packets.

device# configure terminal
device(config)# ptp-clock transparent pkt-type ethernet option e2e step-type onestep
PTP Feature Enabled

device(config)# show access-list tcam acl-name FILTER_PTP_PKT

Ingress:
UnitId Feature         SRule ERule Filters Contiguous RefCnt Bind If
------ -------         ----- ----- ------- ---------- ------ -------
1      PTP             190   191   2       YES        30     e 1/1/1 to 1/1/24 e 1/2/1 to 1/2/4
History
Release version Command history
08.0.95 This command was introduced.
10.0.20 This command is updated with new group parameter changes.