cancel
Showing results forĀ 
Search instead forĀ 
Did you mean:Ā 
cancel
969
Views
0
Helpful
1
Replies

Configure IPV6 port ACL and MAC port ACL on Nexus 31108PC-V

19782401a
Level 1
Level 1

Hi,

I'm tryng to configure apply a IPV6 ACL and MAc ACL on a L2 interface (port ACL), but system give me an error "TCAM region is not configured. Please configure TCAM region and retry the command"

TCAM region IPV6 PACL [ipv6-ifacl] and MAC PACL [mac-ifacl] are in effect set to 0.

Wich correct value have I to set? After this configuration, have I necessarily  rebbot the switch? If yes, to minimize outage is empty non-disrupt reload?

Thanks

Gian Luca

 

1 Accepted Solution

Accepted Solutions

Peter Paluch
Cisco Employee
Cisco Employee

Hi Gian Luca,

You will indeed need to increase the sizes of the ipv6-ifacl and mac-ifacl TCAM regions to a non-zero size; the values need to be multiples of 256, so 256 is the minimum non-zero value. Typically, this will come at the expense of another TCAM region - you will likely need to first decrease the size of some other, potentially unused region, and only then grow the ipv6-ifacl and mac-ifacl regions. What value you should use depends on how many distinct ACLs you plan to use, how many entries they will have, and how complex will those entries be. In a very general way, every ACL entry can take between 1-3 TCAM entries. 

A reload after this change is, sadly, inevitable, and it needs to be a full reload of the chassis.

Changes to TCAM carving are admittedly one of the most annoying configuration changes on the Nexus switch platforms since they always require full reloads and since the configured carving values may need to be repeatedly tweaked.

Best regards,
Peter

View solution in original post

1 Reply 1

Peter Paluch
Cisco Employee
Cisco Employee

Hi Gian Luca,

You will indeed need to increase the sizes of the ipv6-ifacl and mac-ifacl TCAM regions to a non-zero size; the values need to be multiples of 256, so 256 is the minimum non-zero value. Typically, this will come at the expense of another TCAM region - you will likely need to first decrease the size of some other, potentially unused region, and only then grow the ipv6-ifacl and mac-ifacl regions. What value you should use depends on how many distinct ACLs you plan to use, how many entries they will have, and how complex will those entries be. In a very general way, every ACL entry can take between 1-3 TCAM entries. 

A reload after this change is, sadly, inevitable, and it needs to be a full reload of the chassis.

Changes to TCAM carving are admittedly one of the most annoying configuration changes on the Nexus switch platforms since they always require full reloads and since the configured carving values may need to be repeatedly tweaked.

Best regards,
Peter