Filters, QoS, and Security

For more information, see Filter Scaling.

Table 1. Filters, QoS, and Security Maximums

Attribute

Product

Maximum number supported

Total IPv4 Ingress rules/ACEs (Port/VLAN/InVSN based, Security/QoS filters)

5320 Series

48-port models: 3,072

16- and 24-port models: 1,024

5420 Series

2,048 Primary Bank

1,024 Secondary Bank

5520 Series

1,024 Primary Bank

512 Secondary Bank

5720 Series

5720MW Series models

Primary Bank: 3,072

Secondary Bank: 1,536

5720MXW Series models

Primary Bank: 4,096

Secondary Bank: 2,048

7520 Series

Primary Bank: 1,536

Secondary Bank: 1,536

7720 Series

Primary Bank: 1,536

Secondary Bank: 1,536

Total IPv4 Egress rules/ACEs (Port based, Security filters)

5320 Series

48-port models: 400

144 if you enable boot config flags ipv6-egress-filter or boot config flags macsec

16- and 24-port models: 190

62 if you enable boot config flags ipv6-egress-filter or boot config flags macsec

5420 Series

400

144 if you enable boot config flags ipv6-egress-filter or boot config flags macsec

5520 Series

336

80 if you enable boot config flags ipv6-egress-filter

5720 Series

5720MW Series models: 2,982,

1,446 if you enable boot config flags ipv6-egress-filter

5720MXW Series models: 6,000

2,982 if you enable boot config flags ipv6-egress-filter

7520 Series

783

271 if you enable boot config flags ipv6-egress-filter

7720 Series

783

271 if you enable boot config flags ipv6-egress-filter

Total IPv6 Ingress rules/ACEs (Port/VLAN/InVSN based, Security filters)

5320 Series

1,024

5420 Series

512

5520 Series

512

5720 Series

5720MW Series models: 1,536

5720MXW Series models: 2,048

7520 Series

767

7720 Series

767

Total IPv6 egress rules/ACEs (Port based, Security filters)

5320 Series

48-port models: 256, 0 with MACsec

16- and 24-port models: 128, 0 with MACsec

5420 Series

256, 0 with MACsec

5520 Series

256

5720 Series

5720MW Series models: 1,536

5720MXW Series models: 3,072

7520 Series

511

7720 Series

511

EAP (clients per port)
Note:

The total of EAP clients plus NEAP clients per port or per switch cannot exceed 8,192.

5320 Series

32

5420 Series

32

5520 Series

32

5720 Series

32

7520 Series

32

7720 Series

32

Table 2. NEAP Maximums

Product

Max # supported

Details

5320 Series

Note:

The total of EAP clients plus NEAP clients per port or per switch cannot exceed 8,192.

Note:

Resources are shared with Switched UNI Endpoints.

800

boot config flags macsec: NO

boot config flags spbm-node-scaling: NO

Platform VLAN: N/A

800

boot config flags macsec: YES

boot config flags spbm-node-scaling: NO

Platform VLAN: NO

700

boot config flags macsec: YES

boot config flags spbm-node-scaling: NO

Platform VLAN: YES

400

boot config flags macsec: N/A

boot config flags spbm-node-scaling: YES

Platform VLAN: N/A

5420 Series

800

boot config flags macsec: NO

boot config flags spbm-node-scaling: NO

Platform VLAN: N/A

800

boot config flags macsec: YES

boot config flags spbm-node-scaling: NO

Platform VLAN: NO

700

boot config flags macsec: YES

boot config flags spbm-node-scaling: NO

Platform VLAN: YES

400

boot config flags macsec: N/A

boot config flags spbm-node-scaling: YES

Platform VLAN: N/A

5520 Series

4,900

N/A

5720 Series

8,192

N/A

7520 Series

8,192

N/A

7720 Series

8,192

N/A