After these verification steps are performed, the ACL manager considers the command valid and sends the
information to the ACL agent on the line card. The ACL manager notifies the ACL agent in the following
cases:
• A VLAN member is added or removed from a group and previously associated VLANs exist in the group.
• The egress ACL is applied or removed from the group and the group contains VLAN members.
• VLAN members are added or deleted from a VLAN, which itself is a group member.
• A line card returns to the active state after going down and this line card contains a VLAN that is a
member of an ACL group.
• The ACL VLAN group is deleted and it contains VLAN members.
The ACL manager does not notify the ACL agent in the following cases:
• The ACL VLAN group is created.
• The ACL VLAN group is deleted and it does not contain VLAN members.
• The ACL is applied or removed from a group and the ACL group does not contain a VLAN member.
• The description of the ACL group is added or removed.
Guidelines for Configuring ACL VLAN
Groups
Keep the following points in mind when you configure ACL VLAN groups:
• The interfaces where you apply the ACL VLAN group function as restricted interfaces. The ACL VLAN
group name identifies the group of VLANs that performs hierarchical filtering.
• You can add only one ACL to an interface at a time.
• When you attach an ACL VLAN group to the same interface, validation performs to determine whether
the ACL is applied directly to an interface. If you previously applied an ACL separately to the interface, an
error occurs when you attempt to attach an ACL VLAN group to the same interface.
• The maximum number of members in an ACL VLAN group is determined by the type of switch and its
hardware capabilities. This scaling limit depends on the number of slices that are allocated for ACL CAM
optimization. If one slice is allocated, the maximum number of VLAN members is 256 for all ACL VLAN
groups. If two slices are allocated, the maximum number of VLAN members is 512 for all ACL VLAN
groups.
• The maximum number of VLAN groups that you can configure also depends on the hardware
specifications of the switch. Each VLAN group is mapped to a unique ID in the hardware. The maximum
number of ACL VLAN groups supported is 31. Only a maximum of two components (iSCSI counters,
Open Flow, ACL optimization, and so on) can be allocated virtual flow processing slices at a time.
• Port ACL optimization is applicable only for ACLs that are applied without the VLAN range.
• If you enable the ACL VLAN group capability, you cannot view the statistical details of ACL rules per
VLAN and per interface. You can only view the counters per ACL only using the
show ip accounting
access list
command.
Access Control List (ACL) VLAN Groups and Content Addressable Memory (CAM)
131
Содержание S4048T
Страница 1: ...Dell Configuration Guide for the S4048T ON System 9 10 0 1 ...
Страница 98: ... saveenv 7 Reload the system uBoot mode reset Management 98 ...
Страница 113: ...Total CFM Pkts 10303 CCM Pkts 0 LBM Pkts 0 LTM Pkts 3 LBR Pkts 0 LTR Pkts 0 802 1ag 113 ...
Страница 411: ...mode transit no disable Force10 Resilient Ring Protocol FRRP 411 ...
Страница 590: ...Figure 67 Inspecting the LAG Configuration Link Aggregation Control Protocol LACP 590 ...
Страница 591: ...Figure 68 Inspecting Configuration of LAG 10 on ALPHA Link Aggregation Control Protocol LACP 591 ...
Страница 594: ...Figure 70 Inspecting a LAG Port on BRAVO Using the show interface Command Link Aggregation Control Protocol LACP 594 ...
Страница 595: ...Figure 71 Inspecting LAG 10 Using the show interfaces port channel Command Link Aggregation Control Protocol LACP 595 ...
Страница 646: ...Figure 87 Configuring Interfaces for MSDP Multicast Source Discovery Protocol MSDP 646 ...
Страница 647: ...Figure 88 Configuring OSPF and BGP for MSDP Multicast Source Discovery Protocol MSDP 647 ...
Страница 648: ...Figure 89 Configuring PIM in Multiple Routing Domains Multicast Source Discovery Protocol MSDP 648 ...
Страница 653: ...Figure 91 MSDP Default Peer Scenario 2 Multicast Source Discovery Protocol MSDP 653 ...
Страница 654: ...Figure 92 MSDP Default Peer Scenario 3 Multicast Source Discovery Protocol MSDP 654 ...
Страница 955: ...Figure 119 Single and Double Tag First byte TPID Match Service Provider Bridging 955 ...
Страница 1179: ...Figure 147 Create Hypervisor Figure 148 Edit Hypervisor Figure 149 Create Transport Connector Virtual Extensible LAN VXLAN 1179 ...