Filter Scaling

This section provides more details on filter scaling numbers for the supported platforms.

VSP 4450 Series

The switch supports the following maximum limits:

Note

Note

You can configure up to 1000 ACEs in a single ACL.

The switch supports the following maximum limits regarding ingress ACLs (inPort or inVlan):

256 ( InPort security ACE + ACL) + 256 (inVlan security ACE +ACL) + 256 (inPort QoS ACE + ACL) + 256 (inVlan QoS ACE + ACL)

VSP 4900 Series

The switch supports the following maximum limits:

VSP 7400 Series

The switch supports the following maximum limits for ACL scaling:

The switch supports the following maximum limits for ACE scaling:

VSP 7200 Series, VSP 8200 Series, and VSP 8404

The switch supports the following maximum limits:

VSP 8404C

The switch supports a maximum 3,070 non-IPv6 ingress ACEs, 2,047 IPv6 ingress ACEs, and 251 non-IPv6 egress ACEs.

IPv6 ingress and IPv6 egress QoS ACL/Filters are not supported. If you disable an ACL, the ACL state affects the administrative state of all of the ACEs within it.

The switch supports the following maximum limits for ACL scaling:

The switch supports the following maximum limits for ACE scaling:

XA1400 Series

The switch supports the following maximum limits:

Routed Private VLANs/E-TREEs Scaling

The number of private VLANs that you configure with an IP address influences the IPv4 Egress ACE count.

The following table lists scaling limits for Routed Private VLANs/E-TREEs. Limits are not enforced; either number of private VLANs or number of private VLAN trunk ports can go beyond the recommended values.

Table 1. Routed Private VLANs/E-TREEs Maximums

Private VLAN trunk ports

Routed PVLANs/E-TREEs

IPv4 Egress ACE rules available (No IPv6 egress filter bootflag enabled)

IPv4 Egress ACE rules available (With IPv6 egress filter bootflag enabled)

VSP 4900 Series

4

30

97

49

VSP 7200 Series

4

10

147

99

VSP 7400 Series

4

50

532

20

VSP 8200 Series

4

10

181

129

VSP 8400 Series

4

10

181

129

Use the show io resources filter command to verify remaining resources. This command displays the following information:
  • resources consumed by Routed Private VLANs

  • free entries available for either IPv4 Egress ACEs or private VLANs

The following example output displays resource usage on a VSP 7400 Series for ten Routed Private VLANs with four private trunk members each.

Switch:1>show io resources filter
=============================================================================
                                  FILTER TABLE
=============================================================================
-----------------------------------------------------------------------------
ACL Filter Resource Manager stats
----------------------------------------------------------------------------
BCM CAP Group: | ICAP_SEC  | ICAP_QOS  | ICAP_IPv6 | ECAP_SEC  | ECAP_IPv6
   Group Mode: | Double    | Triple    | Triple    | Double    | Double
----------------------------------------------------------------------------
Total Entries  : |   767   |   767     |   767     |     782    |     512
 Free Entries  : |   767   |   767     |   767     |     732    |     512
    In Use     : |     0   |     0     |     0     |      50    |       0
Filter table:
-----------------------------------------------------------------
  ACL |        |Port/Vlan|  Sec  |  QoS  |  All  |
  ID  | Flags  | Members | ACE's | ACE's | ACE's | Type
-----------------------------------------------------------------
-----------------------------------------------------------------

Filter resources used by other features:
-------------------------------------
Feature | Type | Number of entries |
-------------------------------------
 PVlan  | ECAP |         50        |
-------------------------------------