Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Community Member

ACE to Masks Issue in 4506

Hi,

I am using Cisco Catalyst 4506 with 12.2(25)EWA4. I have Sup IV WS-X4515. I am getting issues related to TCAM

Log:-

000561: May 17 07:06:23: %C4K_HWACLMAN-4-ACLHWPROGERR: Input Security: Mnc - hardware TCAM limit, some packet processing will be software switched.

000562: May 17 07:06:23: %C4K_HWACLMAN-4-ACLHWPROGERRREASON: Input(null, 28/Normal) Security: Mnc - insufficient hardware TCAM masks.

Output of 'show platform hardware acl statistics utilization brief'

Entries/Total(%) Masks/Total(%)

----------------- ---------------

Input Acl(PortAndVlan) 0 / 8112 ( 0) 0 / 1014 ( 0)

Input Acl(PortOrVlan) 2147 / 8112 ( 26) 995 / 1014 ( 98)

Input Qos(PortAndVlan) 0 / 8112 ( 0) 0 / 1014 ( 0)

Input Qos(PortOrVlan) 0 / 8112 ( 0) 0 / 1014 ( 0)

Output Acl(PortAndVlan) 0 / 8112 ( 0) 0 / 1014 ( 0)

Output Acl(PortOrVlan) 0 / 8112 ( 0) 0 / 1014 ( 0)

Output Qos(PortAndVlan) 0 / 8112 ( 0) 0 / 1014 ( 0)

Output Qos(PortOrVlan) 0 / 8112 ( 0) 0 / 1014 ( 0)

L4Ops: used 13 out of 64

As per Cisco SupIV document / datasheet for every 8 ACE in Input ACL(PortOfVlan) 1 Mask (TCAM) will be utilized, but before even reaching the ACE limit why TCAM entries are getting full ??

Sarva

1 REPLY
Cisco Employee

Re: ACE to Masks Issue in 4506

Hi Sarva,

It looks as masks entries in TCAM are exhausted. I would suggest to reduce per host ACLs and combine them into the same subnets.

Another thing to look for is the layer4 operands: 'sh platform hardware acl l4ops all'. When all of them are used, the TCAM entry numbers goes high quickly. This may give an idea what resource exactly is close to the limit and what needs to be optimised as the first step.

Please see the link below for more help:

http://www.cisco.com/en/US/docs/switches/lan/catalyst4500/12.2/25ew/configuration/guide/secure.html

HTH,Please rate if it does.

-amit singh

421
Views
0
Helpful
1
Replies
CreatePlease to create content