Precedence for ACL and Rate Limiting Features

ACL features have the following precedence:
  1. OpenFlow has precedence over rACL.
  2. rACL has precedence over policy-based routing.
  3. Policy-based routing has precedence over ACL.
  4. ACL has precedence over VLAN rate limiting.
Rate limiting features have the following precedence:
  1. ACL rate limiting has precedence over BMU storm control.
  2. BMU storm control has precedence over VLAN rate limiting and bridge domain rate limiting.
  3. VLAN rate limiting and bridge domain rate limiting have precedence over port rate limiting.

Rate limiting on an interface or port-channel has precedence over system rate limiting.

All ACL and ACL rate limiting features reside in one of two TCAM databases.

Table 1. TCAM databases and features
Database Feature
TCAM User Layer 3 ACL
Layer 2 ACL
Layer 3 ACL rate limiting
Layer 2 ACL rate limiting
TCAM Control (Ctrl) Layer 3 Ctrl
Layer 2 Ctrl
VLAN rate limiting
Port rate limiting
For intra-database features, priority is based on the entry strength or ordering, such as first come, first served. For inter-database features, when there is a hit in both databases, the device first looks at the following actions: