12-05-2023 03:49 PM
Hi All
I've never done a TCAM reallocation.
I'm a bit stuck on what I should be reallocating to where I need it allocated to.
And trying to add more acl rules, I'm getting the tcam is full.
I've got a pair of n3k in a VPC.
I use a few object-groups, copp-system and primarily ip access-lists.
Internal network configuration only.
They are not external facing I have a firewall for all the NATing.
I would think that i would need to allocate more vacl but according to my utilization report I'm not even using it and it's the ingress SUP that's low.
Could someone help and explain?
# show hardware profile tcam region
sup size = 48
vacl size = 640
ifacl size = 400
qos size = 192
span size = 0
racl size = 1536
e-racl size = 256
e-vacl size = 640
qoslbl size = 0
ipsg size = 0
arpacl size = 0
ipv6-racl size = 0
ipv6-e-racl size = 0
ipv6-sup size = 0
ipv6-qos size = 0
e-qos size = 64
pbr size = 0
ipv6-pbr size = 0
e-ipv6-qos size = 0
e-mac-qos size = 0
e-qos-lite size = 0
mcast-bidir size = 0
ipv6-span size = 0
ipv6-span-l2 size = 0
nat size = 256
rbacl size = 0
copp size = 64
fhs size = 0
Unknown size = 0
arp-storm-acl size = 0
svi size = 0
# show hardware access-list resource utilization
slot 1
=======
INSTANCE 0x0
-------------
ACL Hardware Resource Utilization (Mod 1)
----------------------------------------------------------
Used Free Percent
Utilization
-------------------------------------------------------------------
Ingress IFACL 0 400 0.00
0 0.00
0 0.00
0 0.00
0 0.00
0 0.00
Ingress RACL 522 1014 33.98
0 0.00
0 0.00
0 0.00
0 0.00
0 0.00
Ingress VACL 0 640 0.00
0 0.00
0 0.00
0 0.00
0 0.00
0 0.00
Ingress SUP 44 4 91.66
0 0.00
0 0.00
0 0.00
0 0.00
0 0.00
Ingress QOS IPV4 2 190 1.04
0 0.00
0 0.00
0 0.00
0 0.00
0 0.00
Egress Racl 0 256 0.00
0 0.00
0 0.00
0 0.00
0 0.00
0 0.00
Egress QoS 49 15 76.56
0 0.00
0 0.00
0 0.00
0 0.00
0 0.00
Ingress COPP - Egr SUP 49 15 76.56
0 0.00
0 0.00
0 0.00
0 0.00
0 0.00
Egress VACL 0 640 0.00
0 0.00
0 0.00
0 0.00
0 0.00
0 0.00
Ingress NAT 0 256 0.00
0 0.00
0 0.00
0 0.00
0 0.00
0 0.00
LOU 2 29 6.45
Both LOU Operands 2
Single LOU Operands 0
LOU L4 src port: 0
LOU L4 dst port: 2
LOU L3 packet len: 0
LOU IP tos: 0
LOU IP dscp: 0
LOU ip precedence: 0
LOU ip TTL: 0
TCP Flags 0 16 0.00
L4 op labels, Tcam 0 0 63 0.00
L4 op labels, Tcam 2 8 55 12.69
L4 op labels, Tcam 6 1 62 1.58
Ingress Dest info table 0 512 0.00
Egress Dest info table 0 512 0.00
Solved! Go to Solution.
12-06-2023 07:24 AM - edited 12-06-2023 07:24 AM
This question would have greater visibility in the Switching forum: https://community.cisco.com/t5/switching/bd-p/6016-discussions-lan-switching-routing
12-05-2023 10:04 PM
Any command we will discuss here remember' later you maybe need to return to modify it.
Now
Tcam total size is fix'
We need more room for acl so we need to reduce room of other feature.
Select feature that you dont use it' reduce it room
Then you will get free room to enlarge acl tcam.
MHM
12-06-2023 07:24 AM - edited 12-06-2023 07:24 AM
This question would have greater visibility in the Switching forum: https://community.cisco.com/t5/switching/bd-p/6016-discussions-lan-switching-routing
12-06-2023 02:06 PM - edited 12-06-2023 02:12 PM
Thanks I might move this there so I can get a bit more help.
https://community.cisco.com/t5/switching/new-to-tcam-reallocation-for-nexus-n3k/m-p/4972694#M555743
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide