Displaying TCAM Information for ACLs

You can use different forms of the show access-list tcam command to display information on the following items:

  • IPv4 ACLs
  • IPv6 ACLs
  • MAC ACLs
  • ACLs applied to the CPU
  • ACLs applied to an interface or LAG
  • ACLs applied to a stack unit
  • ACLs applied to incoming traffic
  • ACLs applied to outbound traffic
  • Statistics on ACL rules stored in TCAM

Refer to the following examples for more information.

The following example provides TCAM information for ACL 136. The show access-list tcam acl-name command shows which ports have the ACL programmed in TCAM, the type of ACL, which direction the ACL is applied, and how many rules, including the default rule, are programmed in TCAM for the ACL.

device(config-vlan-222)# show access-list tcam acl-name 136
Ingress
UnitId Feature   SRule ERule Filters Contiguous RefCnt Bind If
------ -------   ----- ----- ------- ---------- ------ -------
1      UACL-IPv4 1123  2125  1003    YES        1      e 1/1/18
2      UACL-IPv4 1123  2125  1003    YES        1      e 2/1/18

The following example provides detailed information for the same ACL. The detailed information includes ACL rules and associated ACL sequence numbers and ports.

device(config-vlan-222)# show access-list tcam acl-name 136 detail
Ingress:
UnitId Region Feature   Filter ID Rule  RefCnt Bind If
------ ------ -------   --------- ----- ------ -------
1      0      UACL-IPv4  8        1123  1      e 1/1/18
1      0      UACL-IPv4 10        1124  1      e 1/1/18
1      0      UACL-IPv4 20        1125  1      e 1/1/18
1      0      UACL-IPv4 30        1126  1      e 1/1/18
1      0      UACL-IPv4 40        1127  1      e 1/1/18
1      0      UACL-IPv4 50        1128  1      e 1/1/18
1      0      UACL-IPv4 60        1129  1      e 1/1/18
1      0      UACL-IPv4 70        1130  1      e 1/1/18
1      0      UACL-IPv4 80        1131  1      e 1/1/18

The following example displays information on TCAM rules for the IPv6 ACL named vlan333-ipv6.

device(config-vlan-333)# show running-config vlan 333                       
vlan 333 by port
 tagged ethe 1/1/10 ethe 2/1/10 ethe 3/1/10 lag 25 
 interface ve 333
 ipv6 access-group vlan333-ipv6 in  <-- Applied VLAN shown in output
 ip access-group vlan333-ipv4 in
 ip access-group frag deny
!
!

device(config-vlan-333)# show access-list tcam acl-name vlan333-ipv6
Ingress:
UnitId Feature   SRule ERule Filters Contiguous RefCnt Bind If                                           
------ -------   ----- ----- ------- ---------- ------ -------
1      UACL-IPv6 641   786   146     YES        1      e 1/1/10
2      UACL-IPv6 1012  1157  146     YES        2      e 2/1/10 e 2/1/38
3      UACL-IPv6 1147  1292  146     YES        2      e 3/1/10 e 3/1/40
device(config-vlan-333)#

The following example shows detailed TCAM information for the same ACL.

device(config-vlan-333)# show access-list tcam acl-name vlan333-ipv6 detail 
Ingress:
UnitId Region Feature         Filter ID Rule  RefCnt Bind If                                           
------ ------ -------         --------- ----- ------ -------                                           
1      0      UACL-IPv6       1         641   1      e 1/1/10                                          
1      0      UACL-IPv6       2         642   1      e 1/1/10                                          
1      0      UACL-IPv6       3         643   1      e 1/1/10                                          
1      0      UACL-IPv6       6         644   1      e 1/1/10                                          
1      0      UACL-IPv6       12        645   1      e 1/1/10                                          
1      0      UACL-IPv6       13        646   1      e 1/1/10                                          
1      0      UACL-IPv6       14        647   1      e 1/1/10      

The following example breaks out TCAM rule information for a MAC ACL found in the running configuration for VLAN 333.

device(config-vlan-333)# show running-config vlan 333
vlan 333 by port
 tagged ethe 1/1/10 ethe 2/1/10 ethe 3/1/10 lag 25 
 interface ve 333
 ipv6 access-group vlan333-ipv6 in
 mac access-group mac_acl in
 ip access-group vlan333-ipv4 in
 ip access-group frag deny
!
!

device(config-vlan-333)# show access-list tcam acl-name mac_acl
Ingress:
UnitId Feature         SRule ERule Filters Contiguous RefCnt Bind If                                           
------ -------         ----- ----- ------- ---------- ------ -------                                           
1      UACL-MAC        1119  1129  11      YES        1      e 1/1/10                                          
2      UACL-MAC        1490  1500  11      YES        2      e 2/1/10 e 2/1/38                                 
3      UACL-MAC        1625  1635  11      YES        2      e 3/1/10 e 3/1/40                                 
device(config-vlan-333)#
device(config-vlan-333)# show access-list tcam acl-name mac_acl detail 
Ingress:
UnitId Region Feature         Filter ID Rule  RefCnt Bind If                                           
------ ------ -------         --------- ----- ------ -------                                           
1      0      UACL-MAC        10        1119  1      e 1/1/10                                          
1      0      UACL-MAC        20        1120  1      e 1/1/10                                          
1      0      UACL-MAC        30        1121  1      e 1/1/10                                          
1      0      UACL-MAC        40        1122  1      e 1/1/10                                          
1      0      UACL-MAC        50        1123  1      e 1/1/10                                          
1      0      UACL-MAC        60        1124  1      e 1/1/10                                          
1      0      UACL-MAC        70        1125  1      e 1/1/10                                          
1      0      UACL-MAC        80        1126  1      e 1/1/10                                          
1      0      UACL-MAC        90        1127  1      e 1/1/10                                          
1      0      UACL-MAC        100       1128  1      e 1/1/10                                          
1      0      UACL-MAC        65001     1129  1      e 1/1/10                                          
2      0      UACL-MAC        10        1490  2      e 2/1/10 e 2/1/38                             ^C
device(config-vlan-333)#

The following example displays TCAM usage for a specified stack unit. Information includes available TCAM space for IPv4, IPv6, and MAC ACLs. For a dual-PP device, the command output includes information on the region (0 or 1).

device# show access-list tcam usage unit 4
UnitId Region Group Id Direction  Type            :            Allocated Total Free
------ ------ -------- ---------  ----            :            --------- ----- ----
4      0      1        Pre-Ingres L2_IPv4 FIlters :            1         512   511
4      0      2        Pre-Ingres VCAP_MISC       :            0        1024  1024
4      0      3        Ingress    IPv4 Filters    :            9        2816  2807 <--
4      0      4        Ingress    IPv6 Filters    :            0        1408  1408 <--
4      0      5        Ingress    L2 Filters      :           30        2816  2786 <--
4      0      6        Ingress    ICAP All Combo  :           51         768   717
4      0      7        Ingress    IPSec Filters   :            0        1408  1408
4      0      8        Egress     IPv4 Filters    :            0         256   256 <--
4      0      9        Egress     IPv6 Filters    :            0         256   256 <--
4      0     10        Egress     L2 Filters      :            3         256   253 <--
4      1      1        Pre-Ingres L2_IPv4 FIlters :            1         512   511
4      1      2        Pre-Ingres VCAP_MISC       :            0        1024  1024
4      1      3        Ingress    IPv4 Filters    :         1031        2816  1785 
4      1      4        Ingress    IPv6 Filters    :            7         896   889 
4      1      6        Ingress    ICAP All Combo  :           51         512   461
4      1      7        Ingress    IPSec Filters   :            0         896   896
4      1      8        Egress     IPv4 Filters    :            4         256   252
4      1      9        Egress     IPv6 Filters    :          247         256     9
4      1     10        Egress     L2 Filters      :            3         256   253
device#

The following example displays TCAM information for a specified interface. Use this command to verify ACLs applied on an interface and how many filters are programmed in TCAM for each ACL.

device# show access-list tcam interface ethernet 4/1/10
Ingress:
UnitId AclName      Feature    SRule ERule  Filters Contiguous Merged Acl
------ -------      -------    ----- -----  ------- ---------- ---------
4      STK_ZTP_0403 ZTP         36    36    1       YES
4      STK_IPC_0401 STK_HIGIG    5     5    1       YES
4      123          UACL-IPv4   84   104   21       YES
4      mac_acl      UACL-MAC   105   115   11       YES

Egress:
UnitId AclName      Feature    SRule ERule Filters Contiguous Merged Acl
------ -------      -------    ----- ----- ------- ---------- ---------
4      140          UACL-IPv4  128   129    2      YES
4      egress       UACL-IPv6  118   127   10      YES

The following example displays more detailed information for the same interface, including all rules and filters (by sequence number) for each ACL bound to the interface.

device# show access-list tcam interface ethernet 4/1/10 detail
Ingress:
UnitId Region AclName        Feature     Filter Id Rule
------ ------ -------        -------     --------- -----
4      1      STK_ZTP_0403   ZTP         1         36
4      1      STK_IPC_0401   STK_HIGIG   1          5
4      1      123            UACL-IPv4  10         84
4      1      123            UACL-IPv4  20         85
4      1      123            UACL-IPv4  30         86
4      1      123            UACL-IPv4  40         87
4      1      123            UACL-IPv4  50         88

The following example displays TCAM information for a specified LAG interface.

device# show access-list tcam interface lag 8060
Ingress:
UnitId AclName     Feature       SRule  ERule Filters Contiguous Merged Acl
------ -------     -------       -----  ----- ------- ---------- ---------
2      qos_dscp_34 QOS-DSCP/PCP   909    909  1       YES
3      qos_dscp_34 QOS-DSCP/PCP   907    907  1       YES

Egress:
UnitId AclName     Feature       SRule  ERule Filters Contiguous Merged Acl
------ -------     -------       -----  ----- ------- ---------- ---------
2      125         UACL-IPv4      1587   1822 236     YES
2      egress      UACL-IPv6      1823   2026 204     YES
3      125         UACL-IPv4      1585   1820 236     YES
3      egress      UACL-IPv6      1821   2024 204     YES
device#

The following example displays detailed information for a specified LAG.

device# show access-list tcam interface lag 8060 detail
Ingress:
UnitId Region AclName     Feature      Filter Id Rule
------ ------ -------     -------      --------- -----
2      0      qos_dscp_34 QOS-DSCP/PCP 10        909
3      0      qos_dscp_34 QOS-DSCP/PCP 10        907

Egress:
UnitId Region AclName     Feature      Filter Id Rule
------ ------ -------     -------      --------- -----
2      0      125         UACL-IPv4      2       1587
2      0      125         UACL-IPv4    110       1588
2      0      125         UACL-IPv4    120       1589

The following example displays a list of all ACLs and associated rules, including default rules, programmed on unit 1 in an inbound direction.

device# show access-list tcam ingress unit 1

Ingress:
UnitId AclName                         Feature      SRule ERule    Filters Contiguous RefCnt Bind If
------ -------                         -------      ----- -----    ------- ---------- ------ -------
1 SFLOW_RULE                           SFLOW        34       34       1    YES        30     e 1/1/1 to 1/1/24 e 1/2/2 e 1/2/4 to 1/2/8
1 INGRESS_CPU_RULE                     CPU_RULES     5        5       1    YES        33     e 1/1/1 to 1/1/24 e 1/2/1 to 1/2/8
1 MANAGEMENT                           UACL-IPv4  3165     3356     192    YES         1     e 1/1/2
1 SYS_MGMT_VLAN                        VLAN          6        6       1    YES        30     e 1/1/1 to 1/1/24 e 1/2/2 e 1/2/4 to 1/2/8
1 SYSTEM-L3-UDP-BC                     UDP_BC       35       35       1    YES        30     e 1/1/1 to 1/1/24 e 1/2/2 e 1/2/4 to 1/2/8
1 SPX_ZTP_0402                         SPX_IPC_MAC  36       36       1    YES        30     e 1/1/1 to 1/1/24 e 1/2/2 e 1/2/4 to 1/2/8
1 STK_ZTP_0403                         ZTP          37       37       1    YES        30     e 1/1/1 to 1/1/24 e 1/2/2 e 1/2/4 to 1/2/8
1 STK_IPC_0401                         STK_HIGIG     7        7       1    YES        30     e 1/1/1 to 1/1/24 e 1/2/2 e 1/2/4 to 1/2/8
1 MCAST_ACL_RULES_IGMP                 IGMP         38       38       1    YES        30     e 1/1/1 to 1/1/24 e 1/2/2 e 1/2/4 to 1/2/8
1 MCAST_ACL_RULES_PIM_V4               PIMV4        39       39       1    YES        30     e 1/1/1 to 1/1/24 e 1/2/2 e 1/2/4 to 1/2/8
1 MCAST_ACL_RULES_RES_MC_V4            RES_MC_V4    40       40       1    YES        30     e 1/1/1 to 1/1/24 e 1/2/2 e 1/2/4 to 1/2/8
1 MCAST_ACL_RULES_SC_SP_MLD_V1         MLD          41       41       2    YES        30     e 1/1/1 to 1/1/24 e 1/2/2 e 1/2/4 to 1/2/8
1 MCAST_ACL_RULES_SC_SP_MLD_V2         MLD          44       44       1    YES        30     e 1/1/1 to 1/1/24 e 1/2/2 e 1/2/4 to 1/2/8
1 MCAST_ACL_RULES_SC_SP_PIM_V6         PIMV6        45       45       1    YES        30     e 1/1/1 to 1/1/24 e 1/2/2 e 1/2/4 to 1/2/8
1 SYS_CPU_VLAN_BPDU                    VLAN         46       46       1    YES         1
1 SYS_PVST                             XSTP         47       47       1    YES        30     e 1/1/1 to 1/1/24 e 1/2/2 e 1/2/4 to 1/2/8
1 SYS_MRP                              MRP           8        8       1    YES        30     e 1/1/1 to 1/1/24 e 1/2/2 e 1/2/4 to 1/2/8
1 SYS_UDLD                             UDLD          9        9       1    YES        30     e 1/1/1 to 1/1/24 e 1/2/2 e 1/2/4 to 1/2/8
1 SYS_EOAM_LOOPBACK                    EOAM         48       48       1    YES        30     e 1/1/1 to 1/1/24 e 1/2/2 e 1/2/4 to 1/2/8
1 SYS_SMAC_SUP                         FDB          10       10       1    YES        30     e 1/1/1 to 1/1/24 e 1/2/2 e 1/2/4 to 1/2/8
1 SYSTEM-L3-IPV6-RES-MC                IPV6_RES_MC  49       49       1    YES        30     e 1/1/1 to 1/1/24 e 1/2/2 e 1/2/4 to 1/2/8
1 SYSTEM-L3-IRDP                       IRDP          1        1       1    YES        30     e 1/1/1 to 1/1/24 e 1/2/2 e 1/2/4 to 1/2/8
1 SYSTEM-L3-ARP-PRIORITY               ARP          11       11       1    YES        30     e 1/1/1 to 1/1/24 e 1/2/2 e 1/2/4 to 1/2/8
1 FLEXAUTH_802.1X_BPDU_RULE_UNIT_1     FLEXAUTH     50       50       1    YES        30     e 1/1/1 to 1/1/24 e 1/2/2 e 1/2/4 to 1/2/8
1 SYS_PROTO_REPRIO                     L2_PROTO     51       52       2    YES        30     e 1/1/1 to 1/1/24 e 1/2/2 e 1/2/4 to 1/2/8
1 L2MCAST-ACL-RULES-SPATHA-SICA-UMC-V6 MC_UMC       53       55       3    YES        30     e 1/1/1 to 1/1/24 e 1/2/2 e 1/2/4 to 1/2/8
1 SYSTEM-L3-ND                         ND           56       58       3    YES        30     e 1/1/1 to 1/1/24 e 1/2/2 e 1/2/4 to 1/2/8
1 scale22                              UACL-IPv6  2357     3160     804    YES         2     e 1/1/11 e 1/2/2
1 131                                  UACL-IPv4  3161     3164       4    YES         2     e 1/1/11 e 1/2/2

The following example displays TCAM information for ACLs applied in an outbound direction on unit 1. The command output shows all ACLs programmed in TCAM for the specified unit in the specified direction, including system default rules.

device# show access-list tcam egress unit 1
Egress:
UnitId AclName           Feature    SRule ERule Filters Contiguous RefCnt Bind If
------ -------           -------    ----- ----- ------- ---------- ------ -------
1      ECPU_PORTID_RULE  CPU_RULES   84    85   2       YES        1
1      ECPU_CLASSID_RULE CPU_RULES   86    86   1       YES        1
device#

The show access-list tcam rule-statistics command is used to display hardware-level accounting statistics. The output is displayed for a specific rule in a specific region on a specific unit.

device# show access-list tcam rule-statistics 3161 unit 1 region 0
Rule: 3161 Stat: 0
device#

The show access-list tcam rule command displays detailed output for each rule programmed in TCAM. The command is local to each unit. The following example displays information on rules for region 0 of unit 1.

device# show access-list tcam rule 3161 unit 1 region 0
EID 0x00000c59: gid=0x3,
slice=0, slice_idx=0xc9, part =0 prio=0x1fe0216, flags=0x210602, Installed, Enabled
tcam: color_indep=1,
StageIngress
InPorts
DATA=0x0000000000000000000000000000000000000000000000000008000000000800
MASK=0x00000000000000000000000000000000000000000000000003fe000001ffffff
Stage
IpType
Offset0: 325 Width0: 4
DATA=0x00000000
MASK=0x0000000e
InterfaceClassL2
Offset0: 32 Width0: 12
DATA=0x0000000e
MASK=0x00000fff
action={act=CosQCpuNew, param0=31(0x1f), param1=0(0x00), param2=0(0x00), param3=0(0x00)}
action={act=SwitchToCpuCancel, param0=0(0x00), param1=0(0x00), param2=0(0x00), param3=0(0x00)}
action={act=DynamicHgTrunkCancel, param0=0(0x00), param1=0(0x00), param2=0(0x00), param3=0(0x00)}
action={act=Drop, param0=0(0x00), param1=0(0x00), param2=0(0x00), param3=0(0x00)}
policer=
statistics={stat id 3079 slice = 6 idx=0 entries=1}{Packets}{Bytes}
device#

The following example displays TCAM information for the ACL cpu-ipv4 applied to incoming traffic on the CPU of the active controller for the stack.

device# configure terminal
device(config)# interface cpu active
device(config-if-cpu-active)# ip access-group cpu-ipv4 in

device(config-if-cpu-active)# show access-list tcam acl-name cpu-ipv4
Egress:
UnitId Feature   SRule ERule Filters Contiguous RefCnt Bind If
------ -------   ----- ----- ------- ---------- ------ -------
1      UACL-IPv4 2218  2220  3       YES        1
2      UACL-IPv4 1250  1252  3       YES        1