ACL Scaling
For each ACL type, there is a software limit to the number of ACLs supported. The maximum number of ACL rules supported also varies with the device. The following table contains scaling information for all ICX devices.
ACL Rule Scaling Limits
Do the values for the 8200 devices also apply to the 8100
devices? Yes
| Security Feature | ICX 8200 | ICX 8100 | ICX 7850 | ICX 7650 | ICX 7550 |
|---|---|---|---|---|---|
| Software Scale | |||||
| Maximum configurable standard numbered IPv4 ACLs | 99 | 99 | 99 | 99 | 99 |
| Maximum configurable extended numbered IPv4 ACLs | 100 | 100 | 100 | 100 | 100 |
| Maximum configurable standard named IPv4 ACLs | 600 | 600 | 600 | 600 | 600 |
| Maximum configurable extended named IPv4 ACLs | 600 | 600 | 600 | 600 | 600 |
| Maximum configurable IPv6 ACLs | 600 | 600 | 600 | 600 | 600 |
| Maximum configurable MAC ACLs | 3,072 | 3,072 | 3,072 | 3,072 | 3,072 |
| Maximum configurable filters per IP ACL (same as system max parameter ip-filter-port) | 2,048 | 2,048 | 2,048 | 2,048 | 2,048 |
| Maximum configurable IP filters (IPv4 and IPv6) for the entire stack across all ACLs (same as system max parameter ip-filter-sys) | 8,192 | 8,192 | 8,192 | 8,192 | 8,192 |
| Maximum configurable filters per MAC ACL (same as system max parameter mac-filter-port) | 256 | 256 | 256 | 256 | 256 |
| Maximum configurable MAC filters for the entire stack across all ACLs (same as system max parameter mac-filter-sys) | 3,072 | 3,072 | 3,072 | 3,072 | 3,072 |
| DHCP Snooping/IPSG/DAI | |||||
| Max DHCP Snooping entries | 32,768 | 32,768 | 32,768 | 32,768 | 32,768 |
| Max number of IP Source Guard entries per device | 1,0241 | 1,0242 | 1,536 | 4,096 | 2,048 |
| Max Dynamic ARP Inspection entries | 32,768 | 32,768 | 32,768 | 32,768 | 32,768 |
| Max Static ARP Inspection entries | 6,000 | 6,000 | 6,000 | 6,000 | 6,000 |
| Maximum configurable filters per SG ACL | 8 | 8 | 8 | 8 | 8 |
| DHCPv6 Snooping/ND Inspection | |||||
| Max DHCPv6 Snooping entries | 32,768 | 32,768 | 32,768 | 32,768 | 16,384 |
| Max IPv6 Neighbor Discovery Inspection entries | 32,768 | 32,768 | 32,768 | 32,768 | 16,384 |
| Max Static IPv6 Neighbor Discovery Inspection entries | 6,000 | 6,000 | 6,000 | 6,000 | 6,000 |
| Max IPv6 Source Guard Entries per device | 512 | 512 | 1,536 | 2,048 | 2,048 |
| Hardware Scale | |||||
| IPv4 ingress TCAM rules per device (IPv4 ACL/IPSG) | 102434 | 10244 | 1,536 | 4,096 | 2,048 |
| IPv6 ingress TCAM rules per device | 51256 | 5126 | 1,536 | 2,048 | 2,048 |
| IPv4 Egress TCAM rules per device | 128 | 128 | 512 | 256 | 256 |
| IPv6 Egress TCAM rules per device | 128 | 128 | 512 | 256 | 256 |
| L2 Ingress TCAM rules per device | 512 | 512 | 1,536 | 1,536 | 2,048 |
ACL Scaling Considerations
Keep the following items in mind when configuring ACLs.
Is there any exception for 8100 devices? No
- All platforms consume 1 TCAM space by default for egress IPv4 and IPv6 groups, which reduces the space available for rules by 1 for IPv4 and IPv6 egress ACLs.
- ICX 8100 and ICX 8200 devices consume 1 TCAM space by default for all groups.
- On ICX 7550 and ICX 7850 devices, when an egress ACL is applied to a VLAN, every ACL rule, including each default rule, is programmed as 2 entries.
- By default, TCAM reserves 5 entries for an IPv4 ingress ACL group and 30 entries for a Layer 2 (MAC) ingress ACL on all ICX platforms.
- Use the
show access-list tcam usage unitid command to review hardware usage before binding an ACL.device(config)# show access-list tcam usage unit 3 UnitId Region Group Id Direction Type : Allocated Total Free ------ ------ -------- --------- ---- : --------- ----- ---- 3 0 1 Pre-Ingres L2_IPv4 FIlters : 2 256 254 3 0 2 Pre-Ingres VCAP_MISC : 8 512 504 3 0 3 Ingress IPv4 Filters : 5 2048 2043 3 0 4 Ingress IPv6 Filters : 0 1280 1280 3 0 5 Ingress L2 Filters : 30 2048 2018 3 0 6 Ingress ICAP All Combo : 51 1024 973 3 0 7 Egress IPv4 Filters : 1 256 255 3 0 8 Egress IPv6 Filters : 1 256 255 3 0 9 Egress L2 Filters : 3 256 253
- Published scale numbers are one dimensional. If IPv4, IPv6, and MAC ACLs are configured on the same device, one-dimensional scaling numbers do not apply to the combined ACLs.
- On an ICX 7850 device, if you migrate to FastIron 08.0.95 or a later release from a FastIron 08.0.92 configuration that contains an IPv4 egress ACL applied to a virtual interface, the 2 TCAM rules originally programmed for the ACL (one ACL rule and one implicit deny rule), are programmed as 4 TCAM rules in the target release configuration, where the ACL will be applied at the VLAN level; that is, 2 rules for the ACL and 2 rules for the implicit deny rule.
- On an ICX 7850 device, if you migrate from FastIron
08.0.92 to FastIron 08.0.95 or a later release, the rules created for an IPv6
egress ACL applied to a virtual interface multiply. For example, if you created
the original IPv6 egress ACL with one rule, the ACL is programmed as 4 rules
in
TCAM for the FastIron 08.0.92 configuration; that is, 1 IPv6 ACL rule and 3
implicit rules. In the resulting configuration for the target release, the IPv6
ACL is applied at the VLAN level, and a total of 8 rules will be created in
TCAM; that is, 2 ACL rules and 6 implicit rules.
Note: On ICX 7850 devices, there is no change in scale when you apply an egress ACL on a physical interface.
- The maximum number of IPv4 Source Guard Entries per ICX 8100-C08PF device is 512. The maximum number of IPv6 Source Guard Entries per ICX 8100-C08PF device is 256. ↩
- The maximum number of IPv4 Source Guard Entries per ICX 8200-C08PF device is 512. The maximum number of IPv6 Source Guard Entries per ICX 8200-C08PF device is 256. ↩
- ICX 8100-C08PF devices support 512 IPv4 ingress TCAM rules (IPv4 ACL) per device. ↩
- ICX 8200-C08PF devices support 512 IPv4 ingress TCAM rules (IPv4 ACL) per device. ↩
- ICX 8100-C08PF devices support 256 IPv6 ingress TCAM rules (IPv6 ACL) per device. ↩
- ICX 8200-C08PF devices support 256 IPv6 ingress TCAM rules (IPv6 ACL) per device. ↩