I'm facing the following problem and before I contact Cisco TAC, I want to drop a line here.
I've got a 3750G-12S running IOS 12.2(37)SE1. It's got two L3 VLAN interfaces. Interface Gi1/0/1 is placed in one VLAN and int gi1/0/2 is placed in the other. I've got a few static routes (about 20) and 3 ACL's. The largest ACL is only 3 rules. I am routing between the two L3 interfaces.
Basically, the setup is a border router connected to our internetlink. Traffic is about 100Mbps sustained, 300Mbps peak.
I've got a second 3750 connected to the same ISP. It's doing the same. Both 3750 use HSRP for redundancy.
Now, when I apply a simple ACL (only 3 rules) to one of the VLAN interfaces, CPU usage shoots up to 70-80%. Furthermore, in the logging I can see the following message (i'm pasting command log as well):
Sep 27 17:05:10: %PARSER-5-CFGLOG_LOGGEDCMD: User:FOO logged command:interface VlanXX
Sep 27 17:05:26: %PARSER-5-CFGLOG_LOGGEDCMD: User:FOO logged command:ip access-group 150 in
Sep 27 17:05:26: %ACLMGR-4-UNLOADING: Unloading ACL input label 255 VLAN interfaces 24 IPv4/Mac feature
Sep 27 17:05:26: %ACLMGR-4-ACLTCAMFULL: ACL TCAM Full. Software Forwarding packets on Input label 255 on L3 L2
Sep 27 17:05:26: %ACLMGR-4-UNLOADING: Unloading ACL input label 255 VLAN interfaces 24 IPv6 feature
Sep 27 17:05:30: %SYS-5-CONFIG_I: Configured from console by FOO on vty0 (x.x.x.x)
I'm not using IPv6. What could be wrong?? This is the ooutput from "sh plat tcam uti"
CAM Utilization for ASIC# 0 Max Used
Unicast mac addresses: 784/6272 15/37
IPv4 IGMP groups + multicast routes: 144/1152 6/26
IPv4 unicast directly-connected routes: 784/6272 15/37
IPv4 unicast indirectly-connected routes: 784/6272 20/103
IPv4 policy based routing aces: 0/0 0/0
IPv4 qos aces: 896/896 18/18
IPv4 security aces: 1024/1024 27/27