
28-47
Catalyst 3550 Multilayer Switch Software Configuration Guide
78-11194-09
Chapter 28 Configuring Network Security with ACLs
Displaying ACL Information
This output from the show fm vlan-label privileged EXEC command shows insufficient room for an
input access group in the hardware:
Switch# show fm vlan-label 1
Unloaded due to merge failure or lack of space:
InputAccessGroup
Input Features:
Interfaces or VLANs: Vl1
Priority:normal
Vlan Map:(none)
Access Group:bigone, 11 VMRs
Multicast Boundary:(none), 0 VMRs
Output Features:
Interfaces or VLANs:
Priority:low
Bridge Group Member:no
Vlan Map:(none)
Access Group:(none), 0 VMRs
This output from the show fm vlan-label privileged EXEC command shows not enough room for the
input access group or the output access group on the label. (Note that the access groups were configured
on two different interfaces. Labels are assigned independently for input and output.)
Switch# show fm label 1
Unloaded due to merge failure or lack of space:
InputAccessGroup OutputAccessGroup
Input Features:
Interfaces or VLANs: Vl1
Priority:normal
Vlan Map:(none)
Access Group:bigone, 11 VMRs
Multicast Boundary:(none), 0 VMRs
Output Features:
Interfaces or VLANs: Vl2
Priority:normal
Bridge Group Member:no
Vlan Map:(none)
Access Group:bigtwo, 11 VMRs
Note
When configuring ACLs on the switch, to allocate maximum hardware resources for ACLs, you can use
the sdm prefer access global configuration command to set the Switch Database Management feature
to the access template. For more information on the SDM templates, see the
Resources for User-Selected Features” section on page 7-27
TCAM Usage
You can display the remaining capacity in a TCAM before or after configuring ACLs, and you can also
display how much space is allotted in the TCAM to a particular interface or VLAN by using the show
tcam privileged EXEC commands.
You can use the show tcam size to display the total size of the regions of TCAM in which the ACLs are
entered.
Switch# show tcam inacl 1 size
Ingress ACL TCAM Size:6592 Entries
To change the amount allocated to various TCAM regions, use the sdm prefer global configuration
command to allocate more resources to ACLs, routing, or Layer 2 switching.