<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Catalst 9300 stack: dACL TCAM utilization in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/catalst-9300-stack-dacl-tcam-utilization/m-p/4039317#M558532</link>
    <description>&lt;P&gt;Agreed some time cisco documentation not update, because vast grown products, sure you can have a chat with TAC if you like to.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 03 Mar 2020 14:16:53 GMT</pubDate>
    <dc:creator>balaji.bandi</dc:creator>
    <dc:date>2020-03-03T14:16:53Z</dc:date>
    <item>
      <title>Catalst 9300 stack: dACL TCAM utilization</title>
      <link>https://community.cisco.com/t5/network-access-control/catalst-9300-stack-dacl-tcam-utilization/m-p/4038609#M558496</link>
      <description>&lt;P&gt;Hi board,&lt;/P&gt;&lt;P&gt;not sure if this question is better suited in the switching forum. Let's give it a try here.&lt;/P&gt;&lt;P&gt;So, the Catalyst 9300 has the following TCAM limits for ACE's&lt;/P&gt;&lt;PRE&gt;Switch#$ show platform hardware fed switch active fwd-asic resource tcam utilization
CAM Utilization for ASIC  [0]
 Table                                              Max Values        Used Values
 --------------------------------------------------------------------------------
[...]
 Security Access Control Entries                      5120            126&lt;/PRE&gt;&lt;P&gt;Are the limits (5120 ACE entries) for the whole stack? For example, if I'm having a single 48 Port 9300 switch, then ~100 ACEs per port are possible. If I'm having a stack with two 48 port members, do I have ~50 ACEs per port or is the number of stack members irrelevant for the maximum number of dACL ACEs?&lt;/P&gt;</description>
      <pubDate>Mon, 02 Mar 2020 14:46:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/catalst-9300-stack-dacl-tcam-utilization/m-p/4038609#M558496</guid>
      <dc:creator>Johannes Luther</dc:creator>
      <dc:date>2020-03-02T14:46:22Z</dc:date>
    </item>
    <item>
      <title>Re: Catalst 9300 stack: dACL TCAM utilization</title>
      <link>https://community.cisco.com/t5/network-access-control/catalst-9300-stack-dacl-tcam-utilization/m-p/4038721#M558499</link>
      <description>&lt;P&gt;5000 of security TCAM Access Control List (ACL) capacity&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;5120 per stack - not per device.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Mar 2020 17:30:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/catalst-9300-stack-dacl-tcam-utilization/m-p/4038721#M558499</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2020-03-02T17:30:10Z</dc:date>
    </item>
    <item>
      <title>Re: Catalst 9300 stack: dACL TCAM utilization</title>
      <link>https://community.cisco.com/t5/network-access-control/catalst-9300-stack-dacl-tcam-utilization/m-p/4039287#M558530</link>
      <description>&lt;P&gt;Hey BB,&lt;/P&gt;&lt;P&gt;thanks for the answer - this is what I also thought, but I found this:&lt;/P&gt;&lt;P&gt;&lt;FONT color="#0000FF"&gt;&lt;EM&gt;&lt;SPAN&gt;"Each switch in the stack optimizes data plane &lt;/SPAN&gt;&lt;SPAN&gt;performance by utilizing its local hardware resources. This includes forwarding tasks&lt;/SPAN&gt;&lt;SPAN&gt;and network services such as QoS and ACL"&lt;/SPAN&gt;&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;SPAN&gt;Source: &lt;A href="https://www.cisco.com/c/dam/en/us/products/collateral/switches/catalyst-9000/nb-06-cat9k-ebook-cte-en.pdf" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/dam/en/us/products/collateral/switches/catalyst-9000/nb-06-cat9k-ebook-cte-en.pdf&lt;/A&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;SPAN&gt;Hmmmm ... maybe I need to open a TAC case for this.&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;SPAN&gt;The documentation is very unclear.&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Mar 2020 13:48:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/catalst-9300-stack-dacl-tcam-utilization/m-p/4039287#M558530</guid>
      <dc:creator>Johannes Luther</dc:creator>
      <dc:date>2020-03-03T13:48:00Z</dc:date>
    </item>
    <item>
      <title>Re: Catalst 9300 stack: dACL TCAM utilization</title>
      <link>https://community.cisco.com/t5/network-access-control/catalst-9300-stack-dacl-tcam-utilization/m-p/4039317#M558532</link>
      <description>&lt;P&gt;Agreed some time cisco documentation not update, because vast grown products, sure you can have a chat with TAC if you like to.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Mar 2020 14:16:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/catalst-9300-stack-dacl-tcam-utilization/m-p/4039317#M558532</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2020-03-03T14:16:53Z</dc:date>
    </item>
    <item>
      <title>Re: Catalst 9300 stack: dACL TCAM utilization</title>
      <link>https://community.cisco.com/t5/network-access-control/catalst-9300-stack-dacl-tcam-utilization/m-p/4041613#M558627</link>
      <description>&lt;P&gt;So I opened a TAC case now and got feedback. Obviously our inital thought were not correct. The book is correct.&lt;/P&gt;&lt;P&gt;Each c9300 stack member &lt;STRONG&gt;uses it's own TCAM resources&lt;/STRONG&gt; for the ACLs on the local ports (I didn't double check this in the lab, yet).&lt;/P&gt;&lt;P&gt;The correct command to verify this is:&lt;/P&gt;&lt;PRE&gt;show platform hardware fed switch &lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;{1|2|3|...}&lt;/STRONG&gt;&lt;/FONT&gt; active fwd-asic resource tcam utilization&lt;/PRE&gt;&lt;P&gt;==&amp;gt; Add the switch number to the output ... God - I feel so stupid right now....&lt;/P&gt;</description>
      <pubDate>Fri, 06 Mar 2020 10:59:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/catalst-9300-stack-dacl-tcam-utilization/m-p/4041613#M558627</guid>
      <dc:creator>Johannes Luther</dc:creator>
      <dc:date>2020-03-06T10:59:06Z</dc:date>
    </item>
    <item>
      <title>Re: Catalst 9300 stack: dACL TCAM utilization</title>
      <link>https://community.cisco.com/t5/network-access-control/catalst-9300-stack-dacl-tcam-utilization/m-p/4112324#M561497</link>
      <description>&lt;P&gt;A little side node:&lt;/P&gt;&lt;P&gt;The configuration guide says:&lt;/P&gt;&lt;P&gt;&lt;FONT color="#0000FF"&gt;&lt;EM&gt;The limit for dACL with stacking is 64 ACEs per dACL per port. The limit without stacking is the number of available TCAM entries which varies based on the other ACL features that are active.&lt;/EM&gt; &lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst9300/software/release/16-12/configuration_guide/sec/b_1612_sec_9300_cg/configuring_ieee_802_1x_port_based_authentication.html" target="_blank" rel="noopener"&gt;Link to config guide&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So independent of the actual TCAM utilization the absolute upper limit is 64 ACEs per port.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jul 2020 08:44:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/catalst-9300-stack-dacl-tcam-utilization/m-p/4112324#M561497</guid>
      <dc:creator>Johannes Luther</dc:creator>
      <dc:date>2020-07-02T08:44:33Z</dc:date>
    </item>
    <item>
      <title>Re: Catalst 9300 stack: dACL TCAM utilization</title>
      <link>https://community.cisco.com/t5/network-access-control/catalst-9300-stack-dacl-tcam-utilization/m-p/5132742#M590134</link>
      <description>&lt;P&gt;Hi, I know this post has been inactive por a while, but I have a question regarding the ACEs supported per port and per device/stack... even if the dACL is the same for multiple ports (considering the users are using the same author policy), are the TCAM resources consumed per each ACE on the dACL? or there is some optimization on the resource consumption? Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jun 2024 17:17:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/catalst-9300-stack-dacl-tcam-utilization/m-p/5132742#M590134</guid>
      <dc:creator>pablohernandez</dc:creator>
      <dc:date>2024-06-17T17:17:32Z</dc:date>
    </item>
  </channel>
</rss>

