Platform Rule Allocation

Table 1. Platform Rule Allocation - 4120, 4220
Table Profile Name Table Name 4120 4220
Default

MAC Rules

IPv6 Rules

IPv4 Rules

L2 Rules

ExtremeXOS App/System Rules

0

0

128

56

1,024 (4 slices)

1,024

0

0

256

184

1,024 (4 slices)

1,024
more-ipv4-less-acl

MAC Rules

IPv6 Rules

IPv4 Rules

L2 Rules

ExtremeXOS App/System Rules

0

0

128

56

1,024 (4 slices)

0

0

256

184

1,024 (4 slices)

1,024
more-ipv4-no-ipv6-less-acl

MAC Rules

IPv6 Rules

IPv4 Rules

L2 Rules

ExtremeXOS App/System Rules

0

0

128

56

1,024 (4 slices)

0

0

256

184

1,024 (4 slices)

1,024
more-ipv4-no-mac-no-ipv6-less-acl

MAC Rules

IPv6 Rules

IPv4 Rules

L2 Rules

ExtremeXOS App/System Rules

0

0

128

56

1,024 (4 slices)

0

0

256

184

1,024 (4 slices)

1,024
more-ipv4-no-ipv6

MAC Rules

IPv6 Rules

IPv4 Rules

L2 Rules

ExtremeXOS App/System Rules

0

0

128

56

1,024 (4 slices)

0

0

256

184

1,024 (4 slices)

1,024
more-ipv4-no-mac-no-ipv6

MAC Rules

IPv6 Rules

IPv4 Rules

L2 Rules

ExtremeXOS App/System Rules

0

0

128

56

1,024 (4 slices)

0

0

256

184

1,024 (4 slices)

1,024
more-mac-no-ipv6

MAC Rules

IPv6 Rules

IPv4 Rules

L2 Rules

ExtremeXOS App/System Rules

0

0

128

56

1,024 (4 slices)

0

0

256

184

1,024 (4 slices)

1,024
more-ipv4-no-l2-less-acl- *

MAC Rules

IPv6 Rules

IPv4 Rules

L2 Rules

ExtremeXOS App/System Rules

0

0

184

0

1,024 (4 slices)

0

0

440

0

1,024 (4 slices)

more-ipv4-no-mac-no-ipv6-no-l2-less-acl- *

MAC Rules

IPv6 Rules

IPv4 Rules

L2 Rules

ExtremeXOS App/System Rules

0

0

184

0

1,024 (4 slices)

0

0

440

0

1,024 (4 slices)

more-ipv4-no-l2 *

MAC Rules

IPv6 Rules

IPv4 Rules

L2 Rules

ExtremeXOS App/System Rules

0

0

184

0

1,024 (4 slices)

0

0

440

0

1,024 (4 slices)

more-ipv4-no-mac-no-ipv6-no-l2 *

MAC Rules

IPv6 Rules

IPv4 Rules

L2 Rules

ExtremeXOS App/System Rules

0

0

184

0

1,024 (4 slices)

0

0

440

0

1,024 (4 slices)

* The L2 rule group normally includes ether-type and port qualifiers. When no-l2 is used, all the ether rules are accounted for in the IPv4 group. If you remove both L2 and IPv4 (no-l2 and no-ipv4), then ether rules are accounted for in the IPv6 group. If you remove L2, IPv4, and IPv6, (no-l2, no-ipv4, no-ipv6), then ether rules are accounted for in the MAC group.

Note: The best possible ExtremeXOS system application/system rules are driven by removing the default system ACL rules (disable dot1p replacement ports all), while keeping these system default ACL rules.
Note: Free ACL-slices are required (excluding the policy utilized slices) for MLAG to function properly. configure policy resource-profile is required.
Table 2. Platform Rule Allocation - 5320, 5420, 5520
Table Profile Name Table Name 5320-48T 5320-16P 5320-24T-4X-XT 5320-24T-24S-4XE-XT
Default

MAC Rules

IPv6 Rules

IPv4 Rules

L2 Rules

ExtremeXOS App/System Rules

512

512

512

440

1,024 (4 slices)

0

0

1,024

952

1,024 (4 slices)

0

0

256

184

1,024 (4 slices)

512

512

512

440

1,024 (4 slices)

1,024

1,024

1,024

952

1,024 (4 slices)

512

512

512

440

1,024 (4 slices)

1,024

1,024

1,024

952

4,096 (4 slices) / 1,024 rules

more-ipv4-less-acl

MAC Rules

IPv6 Rules

IPv4 Rules

L2 Rules

ExtremeXOS App/System Rules

512

512

512

440

0

0

1,024

952

0

0

256

184

1,024 (4 slices)

512

512

512

440

1,024 (4 slices)

1,024

1,024

1,024

952

1,024 (4 slices)

512

512

512

440

1,024 (4 slices)

1,024

1,024

1,024

952

4,096 (4 slices) / 1,024 rules

more-ipv4-no-ipv6-less-acl

MAC Rules

IPv6 Rules

IPv4 Rules

L2 Rules

ExtremeXOS App/System Rules

512

0

1,024

440

0

0

1,024

952

0

0

256

184

1,024 (4 slices)

512

0

1024

440

1,024 (4 slices)

1,024

0

2048

952

1,024 (4 slices)

512

0

1,024

440

1,024 (4 slices)

1,024

0

2,048

952

4,096 (4 slices) / 1,024 rules

more-ipv4-no-mac-no-ipv6-less-acl

MAC Rules

IPv6 Rules

IPv4 Rules

L2 Rules

ExtremeXOS App/System Rules

0

0

1536

440

0

0

1,024

952

0

0

256

184

1,024 (4 slices)

0

0

1536

440

1,024 (4 slices)

0

0

3072

952

1,024 (4 slices)

0

0

1536

440

1,024 (4 slices)

0

0

3,072

952

4,096 (4 slices) / 1,024 rules

more-ipv4-no-ipv6

MAC Rules

IPv6 Rules

IPv4 Rules

L2 Rules

ExtremeXOS App/System Rules

512

0

1,024

440

0

0

1,024

952

0

0

256

184

1,024 (4 slices)

512

0

1024

440

1,024 (4 slices)

1,024

0

2048

952

1,024 (4 slices)

512

0

1,024

440

1,024 (4 slices)

1,024

0

2,048

952

4,096 (4 slices) / 1,024 rules

more-ipv4-no-mac-no-ipv6

MAC Rules

IPv6 Rules

IPv4 Rules

L2 Rules

ExtremeXOS App/System Rules

0

0

1536

440

0

0

1,024

952

0

0

256

184

1,024 (4 slices)

0

0

1536

440

1,024 (4 slices)

0

0

3072

952

1,024 (4 slices)

0

0

1536

440

1,024 (4 slices)

0

0

3,072

952

4,096 (4 slices) / 1,024 rules

more-mac-no-ipv6

MAC Rules

IPv6 Rules

IPv4 Rules

L2 Rules

ExtremeXOS App/System Rules

1,024

0

512

440

0

0

1,024

952

0

0

256

184

1,024 (4 slices)

1024

0

512

440

1,024 (4 slices)

2048

0

1,024

952

1,024 (4 slices)

1,024

0

512

440

1,024 (4 slices)

2,048

0

1,024

952

4,096 (4 slices) / 1,024 rules

more-ipv4-no-l2-less-acl- *

MAC Rules

IPv6 Rules

IPv4 Rules

L2 Rules

ExtremeXOS App/System Rules

N/A N/A

0

0

440

0

1,024 (4 slices)

512

512

952

0

1,024 (4 slices)

1,024

1,024

1976

0

1,024 (4 slices)

512

512

952

0

1,024 (4 slices)

1,024

1,024

1,976

0

4,096 (4 slices) / 1,024 rules

more-ipv4-no-mac-no-ipv6-no-l2-less-acl- *

MAC Rules

IPv6 Rules

IPv4 Rules

L2 Rules

ExtremeXOS App/System Rules

N/A N/A

0

0

440

0

1,024 (4 slices)

0

0

1976

0

1,024 (4 slices)

0

0

4024

0

1,024 (4 slices)

0

0

1976

0

1,024 (4 slices)

0

0

4,024

0

4,096 (4 slices) / 1,024 rules

more-ipv4-no-l2 *

MAC Rules

IPv6 Rules

IPv4 Rules

L2 Rules

ExtremeXOS App/System Rules

0

0

440

0

1,024 (4 slices)

512

512

952

0

1,024 (4 slices)

1,024

1,024

1976

0

1,024 (4 slices)

512

512

952

0

1,024 (4 slices)

1,024

1,024

1,976

0

4,096 (4 slices) / 1,024 rules

more-ipv4-no-mac-no-ipv6-no-l2 *

MAC Rules

IPv6 Rules

IPv4 Rules

L2 Rules

ExtremeXOS App/System Rules

0

0

440

0

1,024 (4 slices)

0

0

1976

0

1,024 (4 slices)

0

0

4024

0

1,024 (4 slices)

0

0

1976

0

1,024 (4 slices)

0

0

4,024

0

4,096 (4 slices) / 1,024 rules

* The L2 rule group normally includes ether-type and port qualifiers. When no-l2 is used, all the ether rules are accounted for in the IPv4 group. If you remove both L2 and IPv4 (no-l2 and no-ipv4), then ether rules are accounted for in the IPv6 group. If you remove L2, IPv4, and IPv6, (no-l2, no-ipv4, no-ipv6), then ether rules are accounted for in the MAC group.

Note: The best possible ExtremeXOS system application/system rules are driven by removing the default system ACL rules (disable dot1p replacement ports all), while keeping these system default ACL rules.
Note: Free ACL-slices are required (excluding the policy utilized slices) for MLAG to function properly. configure policy resource-profile is required.
Table 3. Platform Rule Allocation - 5720, 7520, 7720
Table Profile Name Table Name 5720-MXW 5720-MW 7520-48Y-8C 7520-48XT-6C 7720-32-C
Default

MAC Rules

IPv6 Rules

IPv4 Rules

L2 Rules

ExtremeXOS App/System Rules

2,048

2,048

2,048

1,976

20,480 (10 slices) / 2,048 rules

1,536

1,536

1,536

1,464

6,144 (4 slices) / 1,536 rules

512

512

512

440

2,048 (4 slices)

512

512

512

440

2,048 (4 slices)

512

512

512

440

2,048 (4 slices)

less-acl-more-ipv4

MAC Rules

IPv6 Rules

IPv4 Rules

L2 Rules

ExtremeXOS App/System Rules

2,048

2,048

2,048

1,976

20,480 (10 slices) / 2,048 rules

1,536

1,536

1,536

1,464

6,144 (4 slices) / 1,536 rules

512

512

512

440

512

512

512

440

512

512

512

440

less-acl-more-ipv4-no-ipv6

MAC Rules

IPv6 Rules

IPv4 Rules

L2 Rules

ExtremeXOS App/System Rules

2,048

0

4,096

1,976

20,480 (10 slices) / 2,048 rules

1,536

0

3,072

1,464

6,144 (4 slices) / 1,536 rules

512

0

1,024

440

512

0

1,024

440

512

0

1,024

440

less-acl-more-ipv4-no-mac-no-ipv6

MAC Rules

IPv6 Rules

IPv4 Rules

L2 Rules

ExtremeXOS App/System Rules

0

0

6,144

1,976

20,480 (10 slices) / 2,048 rules

0

0

4,608

1,464

6,144 (4 slices) / 1,536 rules

0

0

1,536

440

0

0

1,536

440

0

0

1,536

440

more-ipv4-no-ipv6

MAC Rules

IPv6 Rules

IPv4 Rules

L2 Rules

ExtremeXOS App/System Rules

2,048

0

4,096

1,976

20,480 (10 slices) / 2,048 rules

1,536

0

3,072

1,464

6,144 (4 slices) / 1,536 rules

510

0

1,024

440

510

0

1,024

440

510

0

1,024

440

more-ipv4-no-mac-no-ipv6

MAC Rules

IPv6 Rules

IPv4 Rules

L2 Rules

ExtremeXOS App/System Rules

0

0

6,144

1,976

20,480 (10 slices) / 2,048 rules

0

0

4,608

1,464

6,144 (4 slices) / 1,536 rules

0

0

1,536

440

2,048 (4 slices)

0

0

1,536

440

2,048 (4 slices)

0

0

1,536

440

2,048 (4 slices)

more-mac-no-ipv6

MAC Rules

IPv6 Rules

IPv4 Rules

L2 Rules

ExtremeXOS App/System Rules

4,096

0

2,048

1,976

20,480 (10 slices) / 2,048 rules

3,072

0

1,536

1,464

6,144 (4 slices) / 1,536 rules

1,024

0

512

440

2,048 (4 slices)

1,024

0

512

440

2,048 (4 slices)

1,024

0

512

440

2,048 (4 slices)

less-acl-more-ipv4-no-l2 *

MAC Rules

IPv6 Rules

IPv4 Rules

L2 Rules

ExtremeXOS App/System Rules

2,048

2,048

4,096

0

20,480 (10 slices) / 2,048 rules

1,536

1,536

3,000

0

6,144 (4 slices) / 1,536 rules

512

512

952

0

512

512

952

0

512

512

952

0

less-acl-more-ipv4-no-mac-no-ipv6-no-l2 *

MAC Rules

IPv6 Rules

IPv4 Rules

L2 Rules

ExtremeXOS App/System Rules

0

0

8,192

0

20,480 (10 slices) / 2,048 rules

0

0

6,072

0

6,144 (4 slices) / 1,536 rules

0

0

1,976

0

0

0

1,976

0

0

0

1,976

0

more-ipv4-no-l2 *

MAC Rules

IPv6 Rules

IPv4 Rules

L2 Rules

ExtremeXOS App/System Rules

2,048

2,048

4,096

0

20,480 (10 slices) / 2,048 rules

1,536

1,536

3,000

0

6,144 (4 slices) / 1,536 rules

512

512

952

0

512

512

952

0

512

512

952

0

more-ipv4-no-mac-no-ipv6-no-l2 *

MAC Rules

IPv6 Rules

IPv4 Rules

L2 Rules

ExtremeXOS App/System Rules

0

0

8,192

0

20,480 (10 slices) / 2,048 rules

0

0

6,072

0

6,144 (4 slices) / 1,536 rules

0

0

1,976

0

2,048 (4 slices)

0

0

1,976

0

2,048 (4 slices)

0

0

1,976

0

2,048 (4 slices)

* The L2 rule group normally includes ether-type and port qualifiers. When no-l2 is used, all the ether rules are accounted for in the IPv4 group. If you remove both L2 and IPv4 (no-l2 and no-ipv4), then ether rules are accounted for in the IPv6 group. If you remove L2, IPv4, and IPv6, (no-l2, no-ipv4, no-ipv6), then ether rules are accounted for in the MAC group.

Note: The best possible ExtremeXOS system application/system rules are driven by removing the default system ACL rules (disable dot1p replacement ports all), while keeping these system default ACL rules.
Note: Free ACL-slices are required (excluding the policy utilized slices) for MLAG to function properly. configure policy resource-profile is required.

For information about the maximum authenticated users per switch, see the Limits table of the ExtremeXOS Release Notes.

In ExtremeXOS 22.4, you can use the profile modifier feature to return resources back to ACL from the specified profile. Use the profile-modifier option in the following command:

configure policy resource-profile [default |less-acl [more-ipv4 | more-ipv4-no-ipv6 | more-ipv4-no-l2 |more-ipv4-no-mac-no-ipv6] | more-ipv4-no-mac-no-ipv6-no-l2 | more-ipv4-no-ipv6 | more-ipv4-no-mac-no-ipv6 | more-mac-no-ipv6] {profile-modifier [{no-mac no_mac} {no-ipv4 no_ipv4} {no-ipv6 no_ipv6} {no-l2 no_l2}]}

To see what profile modifier settings you have configured, use the following command:

show policy resource-profile {[default | less-acl [more-ipv4 |more-ipv4-no-ipv6 | more-ipv4-no-l2 |more-ipv4-no-mac-no-ipv6 | more-ipv4-no-mac-no-ipv6-no-l2] |more-ipv4-no-ipv6 | more-ipv4-no-mac-no-ipv6 | more-mac-no-ipv6] {profile-modifier [ {no-mac} {no-ipv4} {no-ipv6} {no-l2}]}}

The following tables show the maximum number of slices available with the resource profile modifier enabled.

Table 4. Slices Available with Resource Profile Modifier for ExtremeSwitching Universal Switches
Profile Name Max Slices Available No Profile Modifier No-mac No-ipv4 No-ipv6 No-l2 No-mac, no-ipv4 No-mac, no-ipv6 no-mac-- no-l2 No-ipv4, no-ipv6 no-ipv4-no-l2 no-ipv6- no-l2 no-mac-no-ipv4-no-ipv6 no-mac-no-ipv4- no-l2 no-mac-no-ipv6- no-l2 no-ipv4- no-ipv6- no-l2
Default 4 4 3 3 3 3 2 2 2 2 2 2 1 1 1 1
less-acl more-ipv4 4 4 3 3 3 3 2 2 2 2 2 2 1 1 1 1
less-acl-more-ipv4-no-ipv6 4 4 3 2 4 3 1 3 2 2 1 3 1 N/A 2 1
less-acl-more-ipv4- no-l2 4 4 3 2 3 4 1 2 3 1 2 3 N/A 1 2 1
less-acl-more-ipv4-no-mac-no-ipv6 4 4 4 1 4 3 1 4 3 1 N/A 3 1 N/A 3 N/A
less-acl-more-ipv4- no-mac- no-ipv6- no-l2 4 4 4 N/A 4 4 N/A 4 4 N/A N/A 4 N/A N/A 4 N/A
more-ipv4-no-ipv6 4 4 3 2 4 3 1 3 2 2 1 3 1 N/A 2 1
more-ipv4- no-l2 4 4 3 2 3 4 1 2 3 1 2 3 N/A 1 2 1
more-ipv4-no-mac-no-ipv6 4 4 4 1 4 3 1 4 3 1 N/A 3 1 N/A 3 N/A
more-ipv4- no-mac- no-ipv6-no-l2 4 4 4 N/A 4 4 N/A 4 4 N/A N/A 4 N/A N/A 4 N/A
more-mac-no-ipv6 4 4 2 3 4 3 1 2 1 3 2 3 1 N/A 1 2