
28-46
Catalyst 3550 Multilayer Switch Software Configuration Guide
78-11194-09
Chapter 28 Configuring Network Security with ACLs
Displaying ACL Information
When you enter the show fm port-label command for label 4, the display shows which TCAMs have
the feature loaded and which do not:
Switch# show fm port-label 4
Needed in CAM(s):1 3
Loaded into CAM(s):3
Sent to CPU by CAM(s):1
Interfaces: Gi0/3, Gi0/10
IP Access Group:101 379 VMRs
DHCP Broadcast Suppression Disabled.
MAC Access Group:(None) 2 VMRs
The display shows that port label 4 is needed in CAMs 1 and 3, but did not fit into CAM 1, because in
this case CAM 1 already contained entries for other port labels and had less available space than CAM 3.
The output shows that the label is loaded into CAM 3 and that CAM 1 sends packets on this label to the
CPU because the entries for the port ACLs on port label 4 have been unloaded from CAM 1.
VLAN or Router ACL Examples
This example shows how to display the feature manager information for VLAN 1:
Switch# show fm vlan 1
Input VLAN Label:1
Output VLAN Label:0 (default)
Priority:normal
This output from the show fm vlan-label privileged EXEC command shows a merge failure on an input
access group:
Switch# show fm vlan-label 1
Unloaded due to merge failure or lack of space:
InputAccessGroup
Merge Fail:input
Input Features:
Interfaces or VLANs: Vl1
Priority:normal
Vlan Map:(none)
Access Group:131, 6788 VMRs
Multicast Boundary:(none), 0 VMRs
Output Features:
Interfaces or VLANs:
Priority:low
Bridge Group Member:no
Vlan Map:(none)
Access Group:(none), 0 VMRs