Optimized Acl Logging With A Pfc3B; Understanding Oal; Oal Guidelines And Restrictions - Cisco WS-SUP32-GE-3B - Supervisor Engine 32 Software Configuration Manual

Software configuration guide
Hide thumbs Also See for WS-SUP32-GE-3B - Supervisor Engine 32:
Table of Contents

Advertisement

Chapter 31
Understanding Cisco IOS ACL Support
IP packets with a header length of less than five will not be access controlled.
Note

Optimized ACL Logging with a PFC3B

These sections describe optimized ACL logging (OAL):

Understanding OAL

OAL provides hardware support for ACL logging. Unless you configure OAL, packets that require
logging are processed completely in software on the PISA. OAL permits or drops packets in hardware
on the PFC3B and uses an optimized routine to send information to the PISA to generate the logging
messages.

OAL Guidelines and Restrictions

The following guidelines and restrictions apply to OAL:
OL-11439-03
Unless you configure optimized ACL logging (OAL), flows that require logging are processed in
software without impacting nonlogged flow processing in hardware (see the
Logging with a PFC3B" section on page
The forwarding rate for software-processed flows is substantially less than for hardware-processed
flows.
When you enter the show ip access-list command, the match count displayed does not include
packets processed in hardware.
When you enter the show policy-map interface command, sometimes the counters that are
displayed do not include all of the hardware switching platform counters.
Understanding OAL, page 31-3
OAL Guidelines and Restrictions, page 31-3
Configuring OAL, page 31-4
OAL and VACL capture are incompatible. Do not configure both features on the switch. With OAL
configured, use SPAN to capture traffic.
OAL is supported only on the PFC3B.
OAL supports only IPv4 unicast packets.
OAL supports VACL logging of permitted ingress traffic.
OAL does not support port ACLs (PACLs).
OAL does not provide hardware support for the following:
Reflexive ACLs
ACLs used to filter traffic for other features (for example, QoS)
Exception packets (for example, TTL failure and MTU failure)
Packets with IP options
Catalyst Supervisor Engine 32 PISA Cisco IOS Software Configuration Guide, Release 12.2ZY
Optimized ACL Logging with a PFC3B
31-3).
"Optimized ACL
31-3

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Catalyst supervisor engine 32 pisa

Table of Contents