Mypower
S4100
Troubleshooting
Maipu Confidential & Proprietary Information
Page
51
of
124
value after modification is the
integer multiple of 4096.
Fault 5: The ACL control based on flow does not take effect.
Possible Reasons
Judging Methods and Solutions
The ACL with high priority
first processes the data flow
that is expected to be
controlled.
Check the configuration. Delete the ACL with high priority that
may cause problem. The ACL priority processes according to
the order of port
>
VLAN
>
global and MAC ACL
>
IP ACL. Apply
ACL on different objects. For example, the applied ACL on one
object performs the permit action, the applied ACL on one
object performs the deny action, and at last, deny the packet,
regardless of the configured rule on the object with lower
priority. You can use the show acl-object command to view
the configured ACL rule.
Switch#show acl-object
----------------Port--Bind--Instance--------------
PortId-------------------Direction----AclType----AclName
port 1/4 IN MAC mark
port 3/4 IN IP asdf
----------------Vlan--Bind--Instance--------------
VlanId-------------------Direction----AclType----AclName
308 OUT IP test
----------------Global--Bind--Instance--------------
Global-------------------Direction----AclType----AclName
The associated traffic-meter
of ACL exceeds the
maximum value.
For the maximum associated traffic-meter quantity of ACL,
refer to the following supported ACL quantity, flow statistics
and the associated traffic-meter quantity of each slice.
switch#show cap-resource
Priority Module Number Resource Quantity
Module Name
10 2 2 Protocol Send To
Cpu IN
9 12 1 VOICE VLAN IN
8 8 2 ipsg function IN
7 3 1 Port MAC ACL IN
6 4 2 Port IP ACL IN
5 5 2 Port IPV6 ACL IN