Access Control List (ACL) VLAN
Groups and Content Addressable
Memory (CAM)
This section describes the access control list (ACL) virtual local area network (VLAN) group, and content
addressable memory (CAM) enhancements.
Optimizing CAM Utilization During the
Attachment of ACLs to VLANs
To minimize the number of entries in CAM, enable and configure the ACL CAM feature. Use this feature when
you apply ACLs to a VLAN (or a set of VLANs) and when you apply ACLs to a set of ports. The ACL CAM
feature allows you to effectively use the Layer 3 CAM space with VLANs and Layer 2 and Layer 3 CAM space
with ports.
To avoid using too much CAM space, configure ACL VLAN groups into a single group. A class identifier (Class
ID) is assigned for each of the ACLs attached to the VLAN and this Class ID is used as an identifier or locator in
the CAM space instead of the VLAN ID. This method of processing reduces the number of entries in the CAM
area and saves memory space by using the Class ID for filtering in CAM instead of the VLAN ID.
When you apply an ACL separately on the VLAN interface, each ACL has a mapping with the VLAN and you
use more CAM space. To maximize CAM space, create an ACL VLAN group and attach the ACL with the VLAN
members.
The ACL manager application on the router processor (RP1) contains all the state information about all the
ACL VLAN groups that are present. The ACL handler on the control processor (CP) and the ACL agent on the
line cards do not contain any information about the group. After you enter the
acl-vlan-group
command,
the ACL manager application performs the validation. If the command is valid, it is processed and sent to the
agent, if required. If a configuration error is found or if the maximum limit has exceeded for the ACL VLAN
groups present on the system, an error message displays. After you enter the
acl-vlan-group
command,
the ACL manager application verifies the following parameters:
• Whether the CAM profile is set in virtual flow processing (VFP).
• Whether the maximum number of groups in the system is exceeded.
• Whether the maximum number of VLAN numbers permitted per ACL group is exceeded.
• When a VLAN member that is being added is already a part of another ACL group.
7
Access Control List (ACL) VLAN Groups and Content Addressable Memory (CAM)
130
Summary of Contents for S4048T
Page 1: ...Dell Configuration Guide for the S4048T ON System 9 10 0 1 ...
Page 98: ... saveenv 7 Reload the system uBoot mode reset Management 98 ...
Page 113: ...Total CFM Pkts 10303 CCM Pkts 0 LBM Pkts 0 LTM Pkts 3 LBR Pkts 0 LTR Pkts 0 802 1ag 113 ...
Page 411: ...mode transit no disable Force10 Resilient Ring Protocol FRRP 411 ...
Page 590: ...Figure 67 Inspecting the LAG Configuration Link Aggregation Control Protocol LACP 590 ...
Page 646: ...Figure 87 Configuring Interfaces for MSDP Multicast Source Discovery Protocol MSDP 646 ...
Page 647: ...Figure 88 Configuring OSPF and BGP for MSDP Multicast Source Discovery Protocol MSDP 647 ...
Page 653: ...Figure 91 MSDP Default Peer Scenario 2 Multicast Source Discovery Protocol MSDP 653 ...
Page 654: ...Figure 92 MSDP Default Peer Scenario 3 Multicast Source Discovery Protocol MSDP 654 ...
Page 955: ...Figure 119 Single and Double Tag First byte TPID Match Service Provider Bridging 955 ...