<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic No free INGRESS ACL Virtual Slices on X670G2-72x in ExtremeSwitching (EXOS/Switch Engine)</title>
    <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/no-free-ingress-acl-virtual-slices-on-x670g2-72x/m-p/92165#M21413</link>
    <description>Hello,&lt;BR /&gt;
&lt;BR /&gt;
recently we had a problem with re-configuring VRRP for certain VLAN on one switch working in MLAG configuration:&lt;BR /&gt;
&lt;DIV class="threadCode"&gt;&lt;B&gt;code:&lt;/B&gt;&lt;PRE spellcheck="false"&gt;...&lt;BR /&gt; pibSendVirtualMacSourcePacketsToCPU(1:39, 00:00:5e:00:01:02, 1) - bcm_filter_install(0, 3762) returned "Table full".&lt;BR /&gt;...&lt;BR /&gt;&lt;/PRE&gt;&lt;/DIV&gt;&lt;BR /&gt;
&lt;BR /&gt;
&lt;DIV class="threadCode"&gt;&lt;B&gt;code:&lt;/B&gt;&lt;PRE spellcheck="false"&gt;# show access-list usage acl-slice port 1&lt;BR /&gt;Ports 1-72&lt;BR /&gt;Stage: INGRESS&lt;BR /&gt;Slices: Used: 12 Available: 0&lt;BR /&gt;Virtual Slice 0 (physical slice 2) Rules: Used: 1 Available: 511 VLAN statistics&lt;BR /&gt;Virtual Slice 1 (physical slice &lt;span class="lia-unicode-emoji" title=":smiling_face_with_sunglasses:"&gt;😎&lt;/span&gt; Rules: Used: 0 Available: 256 user/other&lt;BR /&gt;Virtual Slice 2 (physical slice 1) Rules: Used: 1 Available: 511 VLAN statistics&lt;BR /&gt;Virtual Slice 3 (physical slice 5) Rules: Used: 0 Available: 256 system&lt;BR /&gt;Virtual Slice 4 (physical slice 0) Rules: Used: 3 Available: 509 user/other&lt;BR /&gt;Virtual Slice 5 (physical slice 9) Rules: Used: 95 Available: 161 system&lt;BR /&gt;Virtual Slice 6 (physical slice 11) Rules: Used: 0 Available: 256 IPv6 MC&lt;BR /&gt;Virtual Slice 7 (physical slice 4) Rules: Used: 4 Available: 252 system&lt;BR /&gt;Virtual Slice 8 (physical slice 6) Rules: Used: 0 Available: 256 system&lt;BR /&gt;Virtual Slice 9 (physical slice 3) Rules: Used: 2 Available: 510 IPv6 MC&lt;BR /&gt;Virtual Slice 10 (physical slice 10) Rules: Used: 4 Available: 252 system&lt;BR /&gt;Virtual Slice 11 (physical slice 7) Rules: Used: 1 Available: 255 user/other&lt;BR /&gt;Stage: EGRESS&lt;BR /&gt;Slices: Used: 1 Available: 3&lt;BR /&gt;Virtual Slice * (physical slice 0) Rules: Used: 0 Available: 256&lt;BR /&gt;Virtual Slice * (physical slice 1) Rules: Used: 0 Available: 256&lt;BR /&gt;Virtual Slice * (physical slice 2) Rules: Used: 0 Available: 256&lt;BR /&gt;Virtual Slice 3 (physical slice 3) Rules: Used: 4 Available: 252 VLAN statistics&lt;BR /&gt;Stage: LOOKUP&lt;BR /&gt;Slices: Used: 0 Available: 4&lt;BR /&gt;Virtual Slice * (physical slice 0) Rules: Used: 0 Available: 256&lt;BR /&gt;Virtual Slice * (physical slice 1) Rules: Used: 0 Available: 256&lt;BR /&gt;Virtual Slice * (physical slice 2) Rules: Used: 0 Available: 256&lt;BR /&gt;Virtual Slice * (physical slice 3) Rules: Used: 0 Available: 256&lt;BR /&gt;Stage: EXTERNAL&lt;BR /&gt;&lt;BR /&gt;Virtual Slice : (*) Physical slice not allocated to any virtual slice.&lt;BR /&gt;&lt;/PRE&gt;&lt;/DIV&gt;&lt;BR /&gt;
&lt;BR /&gt;
&lt;BR /&gt;
We do not use either any user-based ACL nor vlan statistics monitor:&lt;BR /&gt;
&lt;DIV class="threadCode"&gt;&lt;B&gt;code:&lt;/B&gt;&lt;PRE spellcheck="false"&gt;#show configuration detail | include access-list&lt;BR /&gt;enable access-list refresh blackhole&lt;BR /&gt;configure access-list vlan-acl-precedence dedicated&lt;BR /&gt;configure access-list rule-compression port-counters dedicated&lt;BR /&gt;configure access-list action-resolution multiple&lt;BR /&gt;configure access-list zone DOS zone-priority 1&lt;BR /&gt;configure access-list zone SYSTEM zone-priority 2&lt;BR /&gt;configure access-list zone SECURITY zone-priority 3&lt;BR /&gt;configure access-list zone DOS application hal application-priority 1&lt;BR /&gt;configure access-list zone DOS application Dos application-priority 2&lt;BR /&gt;configure access-list zone SYSTEM application Cli application-priority 1&lt;BR /&gt;configure access-list zone SYSTEM application IpSecurity application-priority 2&lt;BR /&gt;configure access-list zone SYSTEM application FIPSnooping application-priority 3&lt;BR /&gt;configure access-list zone SYSTEM application ESVT application-priority 4&lt;BR /&gt;configure access-list zone SYSTEM application NetLogin application-priority 5&lt;BR /&gt;configure access-list zone SYSTEM application HealthCheckLAG application-priority 6&lt;BR /&gt;configure access-list zone SYSTEM application IdentityManager application-priority 7&lt;BR /&gt;configure access-list zone SYSTEM application VMTracking application-priority 8&lt;BR /&gt;configure access-list zone SYSTEM application PolicyManager application-priority 9&lt;BR /&gt;configure access-list zone SYSTEM application OpenFlow application-priority 10&lt;BR /&gt;configure access-list zone SYSTEM application Policy application-priority 11&lt;BR /&gt;configure access-list zone SYSTEM application L2PT_PF application-priority 12&lt;BR /&gt;configure access-list zone SYSTEM application Snmp application-priority 15&lt;BR /&gt;configure access-list zone SYSTEM application Telnet application-priority 16&lt;BR /&gt;configure access-list zone SYSTEM application Http application-priority 17&lt;BR /&gt;configure access-list zone SYSTEM application Ssh2 application-priority 18&lt;BR /&gt;configure access-list zone SYSTEM application VlanManager application-priority 19&lt;BR /&gt;configure access-list zone SECURITY application Sentriant application-priority 1&lt;BR /&gt;configure access-list zone SECURITY application GenericXml application-priority 2&lt;BR /&gt;&lt;/PRE&gt;&lt;/DIV&gt;&lt;BR /&gt;
&lt;BR /&gt;
There are 4 Slices with no rules used:&lt;BR /&gt;
&lt;DIV class="threadCode"&gt;&lt;B&gt;code:&lt;/B&gt;&lt;PRE spellcheck="false"&gt;Virtual Slice 1 (physical slice &lt;span class="lia-unicode-emoji" title=":smiling_face_with_sunglasses:"&gt;😎&lt;/span&gt; Rules: Used: 0 Available: 256 user/other&lt;BR /&gt;Virtual Slice 3 (physical slice 5) Rules: Used: 0 Available: 256 system&lt;BR /&gt;Virtual Slice 6 (physical slice 11) Rules: Used: 0 Available: 256 IPv6 MC&lt;BR /&gt;Virtual Slice 8 (physical slice 6) Rules: Used: 0 Available: 256 system&lt;BR /&gt;&lt;/PRE&gt;&lt;/DIV&gt;&lt;BR /&gt;
&lt;BR /&gt;
Is it normal behavior? How could we release some unused Virtlua Slices ?&lt;BR /&gt;
The X670G2-72x is running on 22.5.1.7&lt;BR /&gt;
&lt;BR /&gt;
Regards,&lt;BR /&gt;
Maciej</description>
    <pubDate>Mon, 07 Oct 2019 15:27:05 GMT</pubDate>
    <dc:creator>bagro</dc:creator>
    <dc:date>2019-10-07T15:27:05Z</dc:date>
    <item>
      <title>No free INGRESS ACL Virtual Slices on X670G2-72x</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/no-free-ingress-acl-virtual-slices-on-x670g2-72x/m-p/92165#M21413</link>
      <description>Hello,&lt;BR /&gt;
&lt;BR /&gt;
recently we had a problem with re-configuring VRRP for certain VLAN on one switch working in MLAG configuration:&lt;BR /&gt;
&lt;DIV class="threadCode"&gt;&lt;B&gt;code:&lt;/B&gt;&lt;PRE spellcheck="false"&gt;...&lt;BR /&gt; pibSendVirtualMacSourcePacketsToCPU(1:39, 00:00:5e:00:01:02, 1) - bcm_filter_install(0, 3762) returned "Table full".&lt;BR /&gt;...&lt;BR /&gt;&lt;/PRE&gt;&lt;/DIV&gt;&lt;BR /&gt;
&lt;BR /&gt;
&lt;DIV class="threadCode"&gt;&lt;B&gt;code:&lt;/B&gt;&lt;PRE spellcheck="false"&gt;# show access-list usage acl-slice port 1&lt;BR /&gt;Ports 1-72&lt;BR /&gt;Stage: INGRESS&lt;BR /&gt;Slices: Used: 12 Available: 0&lt;BR /&gt;Virtual Slice 0 (physical slice 2) Rules: Used: 1 Available: 511 VLAN statistics&lt;BR /&gt;Virtual Slice 1 (physical slice &lt;span class="lia-unicode-emoji" title=":smiling_face_with_sunglasses:"&gt;😎&lt;/span&gt; Rules: Used: 0 Available: 256 user/other&lt;BR /&gt;Virtual Slice 2 (physical slice 1) Rules: Used: 1 Available: 511 VLAN statistics&lt;BR /&gt;Virtual Slice 3 (physical slice 5) Rules: Used: 0 Available: 256 system&lt;BR /&gt;Virtual Slice 4 (physical slice 0) Rules: Used: 3 Available: 509 user/other&lt;BR /&gt;Virtual Slice 5 (physical slice 9) Rules: Used: 95 Available: 161 system&lt;BR /&gt;Virtual Slice 6 (physical slice 11) Rules: Used: 0 Available: 256 IPv6 MC&lt;BR /&gt;Virtual Slice 7 (physical slice 4) Rules: Used: 4 Available: 252 system&lt;BR /&gt;Virtual Slice 8 (physical slice 6) Rules: Used: 0 Available: 256 system&lt;BR /&gt;Virtual Slice 9 (physical slice 3) Rules: Used: 2 Available: 510 IPv6 MC&lt;BR /&gt;Virtual Slice 10 (physical slice 10) Rules: Used: 4 Available: 252 system&lt;BR /&gt;Virtual Slice 11 (physical slice 7) Rules: Used: 1 Available: 255 user/other&lt;BR /&gt;Stage: EGRESS&lt;BR /&gt;Slices: Used: 1 Available: 3&lt;BR /&gt;Virtual Slice * (physical slice 0) Rules: Used: 0 Available: 256&lt;BR /&gt;Virtual Slice * (physical slice 1) Rules: Used: 0 Available: 256&lt;BR /&gt;Virtual Slice * (physical slice 2) Rules: Used: 0 Available: 256&lt;BR /&gt;Virtual Slice 3 (physical slice 3) Rules: Used: 4 Available: 252 VLAN statistics&lt;BR /&gt;Stage: LOOKUP&lt;BR /&gt;Slices: Used: 0 Available: 4&lt;BR /&gt;Virtual Slice * (physical slice 0) Rules: Used: 0 Available: 256&lt;BR /&gt;Virtual Slice * (physical slice 1) Rules: Used: 0 Available: 256&lt;BR /&gt;Virtual Slice * (physical slice 2) Rules: Used: 0 Available: 256&lt;BR /&gt;Virtual Slice * (physical slice 3) Rules: Used: 0 Available: 256&lt;BR /&gt;Stage: EXTERNAL&lt;BR /&gt;&lt;BR /&gt;Virtual Slice : (*) Physical slice not allocated to any virtual slice.&lt;BR /&gt;&lt;/PRE&gt;&lt;/DIV&gt;&lt;BR /&gt;
&lt;BR /&gt;
&lt;BR /&gt;
We do not use either any user-based ACL nor vlan statistics monitor:&lt;BR /&gt;
&lt;DIV class="threadCode"&gt;&lt;B&gt;code:&lt;/B&gt;&lt;PRE spellcheck="false"&gt;#show configuration detail | include access-list&lt;BR /&gt;enable access-list refresh blackhole&lt;BR /&gt;configure access-list vlan-acl-precedence dedicated&lt;BR /&gt;configure access-list rule-compression port-counters dedicated&lt;BR /&gt;configure access-list action-resolution multiple&lt;BR /&gt;configure access-list zone DOS zone-priority 1&lt;BR /&gt;configure access-list zone SYSTEM zone-priority 2&lt;BR /&gt;configure access-list zone SECURITY zone-priority 3&lt;BR /&gt;configure access-list zone DOS application hal application-priority 1&lt;BR /&gt;configure access-list zone DOS application Dos application-priority 2&lt;BR /&gt;configure access-list zone SYSTEM application Cli application-priority 1&lt;BR /&gt;configure access-list zone SYSTEM application IpSecurity application-priority 2&lt;BR /&gt;configure access-list zone SYSTEM application FIPSnooping application-priority 3&lt;BR /&gt;configure access-list zone SYSTEM application ESVT application-priority 4&lt;BR /&gt;configure access-list zone SYSTEM application NetLogin application-priority 5&lt;BR /&gt;configure access-list zone SYSTEM application HealthCheckLAG application-priority 6&lt;BR /&gt;configure access-list zone SYSTEM application IdentityManager application-priority 7&lt;BR /&gt;configure access-list zone SYSTEM application VMTracking application-priority 8&lt;BR /&gt;configure access-list zone SYSTEM application PolicyManager application-priority 9&lt;BR /&gt;configure access-list zone SYSTEM application OpenFlow application-priority 10&lt;BR /&gt;configure access-list zone SYSTEM application Policy application-priority 11&lt;BR /&gt;configure access-list zone SYSTEM application L2PT_PF application-priority 12&lt;BR /&gt;configure access-list zone SYSTEM application Snmp application-priority 15&lt;BR /&gt;configure access-list zone SYSTEM application Telnet application-priority 16&lt;BR /&gt;configure access-list zone SYSTEM application Http application-priority 17&lt;BR /&gt;configure access-list zone SYSTEM application Ssh2 application-priority 18&lt;BR /&gt;configure access-list zone SYSTEM application VlanManager application-priority 19&lt;BR /&gt;configure access-list zone SECURITY application Sentriant application-priority 1&lt;BR /&gt;configure access-list zone SECURITY application GenericXml application-priority 2&lt;BR /&gt;&lt;/PRE&gt;&lt;/DIV&gt;&lt;BR /&gt;
&lt;BR /&gt;
There are 4 Slices with no rules used:&lt;BR /&gt;
&lt;DIV class="threadCode"&gt;&lt;B&gt;code:&lt;/B&gt;&lt;PRE spellcheck="false"&gt;Virtual Slice 1 (physical slice &lt;span class="lia-unicode-emoji" title=":smiling_face_with_sunglasses:"&gt;😎&lt;/span&gt; Rules: Used: 0 Available: 256 user/other&lt;BR /&gt;Virtual Slice 3 (physical slice 5) Rules: Used: 0 Available: 256 system&lt;BR /&gt;Virtual Slice 6 (physical slice 11) Rules: Used: 0 Available: 256 IPv6 MC&lt;BR /&gt;Virtual Slice 8 (physical slice 6) Rules: Used: 0 Available: 256 system&lt;BR /&gt;&lt;/PRE&gt;&lt;/DIV&gt;&lt;BR /&gt;
&lt;BR /&gt;
Is it normal behavior? How could we release some unused Virtlua Slices ?&lt;BR /&gt;
The X670G2-72x is running on 22.5.1.7&lt;BR /&gt;
&lt;BR /&gt;
Regards,&lt;BR /&gt;
Maciej</description>
      <pubDate>Mon, 07 Oct 2019 15:27:05 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/no-free-ingress-acl-virtual-slices-on-x670g2-72x/m-p/92165#M21413</guid>
      <dc:creator>bagro</dc:creator>
      <dc:date>2019-10-07T15:27:05Z</dc:date>
    </item>
  </channel>
</rss>

