62-10
Catalyst 4500 Series Switch, Cisco IOS Software Configuration Guide - Cisco IOS XE 3.9.xE and IOS 15.2(5)Ex
Chapter 62 Configuring Network Security with ACLs
TCAM Programming and ACLs
TCAM Programming and ACLs
You apply three types of hardware resources when you program ACLs and ACL-based features: mapping
table entries (MTEs), profiles, and TCAM value/mask entries. If any of these resources are exhausted,
packets are sent to the CPU for software-based processing.
Note
Supervisor Engine 6-E, Supervisor Engine 6L-E, Supervisor Engine 7-E, Supervisor Engine 7L-E, and
Supervisor Engine 8-E automatically manage the available resources. Because masks are not shared on
the supervisor engines, only one programming algorithm exists. No regions exist so region resizing is
not needed.
If you exhaust resources on the supervisor engine, you should consider reducing the complexity of your
configuration.
Note
When an interface is in down state, TCAMs are not consumed for RACLs, but are for PACLs.
Layer 4 Operators in ACLs
The following sections provide guidelines and restrictions for configuring ACLs that include Layer 4
port operations:
•
Restrictions for Layer 4 Operations, page 62-11
•
Configuration Guidelines for Layer 4 Operations, page 62-12
•
Using ACLs to Filter TCP Flags and How ACL Processing Impacts CPU, page 62-13
52 PermitProtTunnel
Y
0
ControlPktsTwo
53 CaptureCgmp
N
440
ControlPktsTwo
55 CaptureIgmp
N
0
ControlPktsTwo
0 IgmpPimv1ToCpu
N
N/A
0 (estimate)
0 IgmpGeneralQueryToCpu
N
N/A
0 (estimate)
2 IgmpToCpu
N
N/A
0 (estimate)
3 IgmpPimv2ToCpu
N
N/A
0 (estimate)
2048 Ipv6MldGeneralQueryCopyToCpu
N
N/A
0 (estimate)
2050 Ipv6MldGeneralQueryCopyToCpu
N
N/A
0 (estimate)
2052 Ipv6MldQueryOrReportV1ToCpu
N
N/A
0 (estimate)
2054 Ipv6MldQueryOrReportV1ToCpu
N
N/A
0 (estimate)
2056 Ipv6MldReportV2ToCpu
N
N/A
0 (estimate)
2058 Ipv6MldReportV2ToCpu
N
N/A
0 (estimate)
2060 Ipv6MldDoneToCpu
N
N/A
0 (estimate)
2064 Ipv6MldPimv2ToCpu
N
N/A
0 (estimate)
CamIndex Entry Type
Active
Hit Count
CamRegion
Summary of Contents for Catalyst 4500 Series
Page 2: ......
Page 4: ......
Page 2086: ...Index IN 46 Software Configuration Guide Release IOS XE 3 9 0E and IOS 15 2 5 E ...