<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic RE: Error: ACL install operation failed - filter hardware full for vlan *, port 1:5 in ExtremeSwitching (EXOS/Switch Engine)</title>
    <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/error-acl-install-operation-failed-filter-hardware-full-for-vlan/m-p/15348#M109</link>
    <description>Hello Martin,&lt;BR /&gt;
&lt;BR /&gt;
as you can see in show access-list usage acl-slice the X440 does not have egress slices available (0).&lt;BR /&gt;
From the manual the X440 is not listed as being capable to do egress ACL:&lt;BR /&gt;
egress &lt;BR /&gt;
Apply the ACL to packets leaving the switch from this interface.(BlackDiamond X8 series switches, BlackDiamond 8000 c-, xl-, xm-series&lt;BR /&gt;
modules, E4G-200 and E4G-400 switches, and Summit X460, X460-G2, X480, X670, X670-G2, and X770 switches only).&lt;BR /&gt;</description>
    <pubDate>Thu, 17 Sep 2015 14:06:00 GMT</pubDate>
    <dc:creator>OscarK</dc:creator>
    <dc:date>2015-09-17T14:06:00Z</dc:date>
    <item>
      <title>Error: ACL install operation failed - filter hardware full for vlan *, port 1:5</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/error-acl-install-operation-failed-filter-hardware-full-for-vlan/m-p/15347#M108</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;Do you know any reason why I am getting this error whenever I try to apply the ACL on egress?&lt;BR /&gt;&lt;BR /&gt;I've tried creating an ACL via a policy and dynamic, with and without logging but I get the same error each time, yet on ingress I can apply an ACL fine - am hitting some limitation on applying ACL on egress, or have my configuration wrong in some manner?&lt;BR /&gt;&lt;BR /&gt;I have the following line in my config:&lt;BR /&gt;&lt;BR /&gt;configure access-list vlan-acl-precedence shared&lt;BR /&gt;&lt;BR /&gt;Which is meant to fix this issue?&lt;BR /&gt;&lt;A href="https://extremeportal.force.com/ExtrArticleDetail?an=000063193" target="_blank" rel="nofollow noreferrer noopener"&gt;https://extremeportal.force.com/ExtrArticleDetail?an=000063193&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Creation and application of dynamic ACL:&lt;BR /&gt;&lt;BR /&gt;create access-list Debug-Port-Egress " source-address 0.0.0.0/0 ;" " permit ; log ; mirror-cpu ; count Debug-Port-Egress ;" application "Cli"&lt;BR /&gt;&lt;BR /&gt;configure access-list add "Debug-Port-Egress" first ports 1:5 egress&lt;BR /&gt;Error: ACL install operation failed - filter hardware full for vlan *, port 1:5&lt;BR /&gt;&lt;BR /&gt;Creation and application of ACL through policy:&lt;BR /&gt;&lt;BR /&gt;With logging:&lt;BR /&gt;&lt;BR /&gt;entry Debug-Port-egress {&lt;BR /&gt;if match all {&lt;BR /&gt;source-address 0.0.0.0/0;&lt;BR /&gt;} then {&lt;BR /&gt;permit ;&lt;BR /&gt;log ;&lt;BR /&gt;mirror-cpu ;&lt;BR /&gt;count Debug-Port-Ingress ;&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;&lt;BR /&gt;And without logging&lt;BR /&gt;&lt;BR /&gt;entry Debug-Port-egress {&lt;BR /&gt;if match all {&lt;BR /&gt;source-address 0.0.0.0/0;&lt;BR /&gt;} then {&lt;BR /&gt;permit ;&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;configure access-list Debug-Port-Egress ports 1:5 egress&lt;BR /&gt;&lt;BR /&gt;Error: ACL install operation failed - filter hardware full for vlan *, port 1:5&lt;BR /&gt;&lt;BR /&gt;And show commands that you might find useful:&lt;BR /&gt;&lt;BR /&gt;Stack 1.41 # show access-list configuration&lt;BR /&gt;Access-list Refresh Blackhole: Enabled&lt;BR /&gt;Access-list Permit To-CPU: Enabled&lt;BR /&gt;&lt;BR /&gt;Access-list configured vlan-acl-precedence mode: Shared&lt;BR /&gt;Access-list operational vlan-acl-precedence mode: Shared&lt;BR /&gt;Access-list Rule-compression Port-counters: Dedicated&lt;BR /&gt;&lt;BR /&gt;Stack 1.40 # show access-list usage acl-slice port 1:5&lt;BR /&gt;Ports 1:1-1:24&lt;BR /&gt;Stage: INGRESS&lt;BR /&gt;Slices: Used: 2 Available: 2&lt;BR /&gt;Slice 0 Rules: Used: 0 Available: 0&lt;BR /&gt;Slice 1 Rules: Used: 0 Available: 0&lt;BR /&gt;Slice 2 Rules: Used: 17 Available: 239 system&lt;BR /&gt;Slice 3 Rules: Used: 70 Available: 186 user/other&lt;BR /&gt;Stage: EGRESS&lt;BR /&gt;Slices: Used: 0 Available: 0&lt;BR /&gt;Stage: LOOKUP&lt;BR /&gt;Slices: Used: 0 Available: 0&lt;BR /&gt;Stage: EXTERNAL&lt;BR /&gt;Slices: Used: 0 Available: 0&lt;BR /&gt;&lt;BR /&gt;Stack 1.39 # show access-list dynamic&lt;BR /&gt;Dynamic Rules: ((*)- Rule is non-permanent )&lt;BR /&gt;&lt;BR /&gt;Debug-Port-Egress Bound to 0 interfaces for application Cli&lt;BR /&gt;Debug-Port-Ingress Bound to 1 interfaces for application Cli&lt;BR /&gt;(*)hclag_arp_2_4_96_82_46_c1 Bound to 0 interfaces for application HealthCheckLAG&lt;BR /&gt;(*)idmgmt_def_blacklist Bound to 0 interfaces for application IdentityManager&lt;BR /&gt;(*)idmgmt_def_whitelist Bound to 0 interfaces for application IdentityManager&lt;BR /&gt;&lt;BR /&gt;Switch is a stack of 4 x X440, running version 15.5.4.2 patch 1-5&lt;BR /&gt;&lt;BR /&gt;Many thanks in advance&lt;/P&gt;</description>
      <pubDate>Thu, 17 Sep 2015 13:59:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/error-acl-install-operation-failed-filter-hardware-full-for-vlan/m-p/15347#M108</guid>
      <dc:creator>Anonymous</dc:creator>
      <dc:date>2015-09-17T13:59:00Z</dc:date>
    </item>
    <item>
      <title>RE: Error: ACL install operation failed - filter hardware full for vlan *, port 1:5</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/error-acl-install-operation-failed-filter-hardware-full-for-vlan/m-p/15348#M109</link>
      <description>Hello Martin,&lt;BR /&gt;
&lt;BR /&gt;
as you can see in show access-list usage acl-slice the X440 does not have egress slices available (0).&lt;BR /&gt;
From the manual the X440 is not listed as being capable to do egress ACL:&lt;BR /&gt;
egress &lt;BR /&gt;
Apply the ACL to packets leaving the switch from this interface.(BlackDiamond X8 series switches, BlackDiamond 8000 c-, xl-, xm-series&lt;BR /&gt;
modules, E4G-200 and E4G-400 switches, and Summit X460, X460-G2, X480, X670, X670-G2, and X770 switches only).&lt;BR /&gt;</description>
      <pubDate>Thu, 17 Sep 2015 14:06:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/error-acl-install-operation-failed-filter-hardware-full-for-vlan/m-p/15348#M109</guid>
      <dc:creator>OscarK</dc:creator>
      <dc:date>2015-09-17T14:06:00Z</dc:date>
    </item>
    <item>
      <title>RE: Error: ACL install operation failed - filter hardware full for vlan *, port 1:5</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/error-acl-install-operation-failed-filter-hardware-full-for-vlan/m-p/15349#M110</link>
      <description>Oh, ok, thanks Oscar, that explains that nicely then &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Thu, 17 Sep 2015 14:21:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/error-acl-install-operation-failed-filter-hardware-full-for-vlan/m-p/15349#M110</guid>
      <dc:creator>Anonymous</dc:creator>
      <dc:date>2015-09-17T14:21:00Z</dc:date>
    </item>
  </channel>
</rss>

