06-08-2016 02:20 AM - edited 03-08-2019 06:07 AM
Hello Support Team,
I've a Nexus-Pair, PID N5K-C5596UP, with some Fex-Switches attached to it. We configure them to act as Vlan-Termination point with a total of 71 SVIs (Vlan-interfaces). To 62 of them we attached an ACL to the interface. As we tried to do the same with the 63th interface we saw this error:
%AFM-3-AFM_VERIFY_FAIL: Access control policy modification on vlan 1021 failed
%ACLMGR-3-ACLMGR_VERIFY_FAIL: Verify failed: no free label
We thought it could have been an NX-OS Bug (this one: CSCus09017) so we updated the OS from 7.0.5.N1.1 to 7.2.1.N1.1 (see below) but the error persisted.
kickstart: version 7.2(1)N1(1)
system: version 7.2(1)N1(1)
Does someone has a tipp on how can I solve this problem?
Thanks in advanced!
Lutz
02-12-2018 02:18 AM - edited 02-12-2018 02:20 AM
Same problem here:
Pair of N5548UP both with version 7.1(4)N1(1)
Created a new vlan + svi + acl for it.
on switch2 everything went normally
on switch1 (where pbr is enabled for testing) I could create the VLAN + SVI but not apply the ACL on it.
%AFM-3-AFM_VERIFY_FAIL: Access control policy modification on vlan 360 failed
%ACLMGR-3-ACLMGR_VERIFY_FAIL: Verify failed: no free label
PBR is currently enabled on no interface.
Total VLANs: 17
Thanks in advance,
Marcel
05-03-2018 03:30 AM
Reboot will help ...
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide