Hardware And Software Acl Support - Cisco Catalyst 4500 Series Configuration Manual

Release ios xe 3.3.0sg and ios 15.1(1)sg
Hide thumbs Also See for Catalyst 4500 Series:
Table of Contents

Advertisement

Hardware and Software ACL Support

Hardware and Software ACL Support
This section describes how to determine whether ACLs are processed in hardware or in software:
Note
Packets that require logging are processed in software. A copy of the packets is sent to the CPU for
logging while the actual packets are forwarded in hardware so that non-logged packet processing is not
impacted.
By default, the Catalyst 4500 series switch sends ICMP unreachable messages when a packet is denied
by an access list; these packets are not dropped in hardware but are forwarded to the switch so that it can
generate the ICMP unreachable message.
To drop access list denied packets in hardware on the input interface, you must disable ICMP
unreachable messages using the no ip unreachables interface configuration command. The
ip unreachables command is enabled by default.
Cisco IOS Release 12.2(40)SG does not support disabling IP unreachables on interfaces routing IPv6
Note
traffic.
Note
If you set the no ip unreachable command on all Layer 3 interfaces, output ACL denied packets do not
come to the CPU.
Troubleshooting High CPU Due to ACLs
Packets that match entries in fully programmed ACLs are processed in hardware.
Note
Large ACL and IPSG configurations may exhaust TCAM masks on the Catalyst 4948E Ethernet Switch
before the ACLs are fully programmed.
Software Configuration Guide—Release IOS XE 3.3.0SG and IOS 15.1(1)SG
51-6
Flows that match a deny statement in standard and extended ACLs are dropped in hardware if ICMP
unreachable messages are disabled.
Flows that match a permit statement in standard ACLs are processed in hardware.
The following ACL types are not supported in software:
Standard Xerox Network Systems (XNS) Protocol access list
Extended XNS access list
DECnet access list
Protocol type-code access list
Standard Internet Packet Exchange (IPX) access list
Extended IPX access list
Chapter 51
Configuring Network Security with ACLs
OL-25340-01

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents