<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic RE: ACL slices in ExtremeSwitching (EXOS/Switch Engine)</title>
    <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/acl-slices/m-p/28212#M4294</link>
    <description>Create Date: Aug 23 2013  5:50PM&lt;BR /&gt;
&lt;BR /&gt;
For my knowledge different slices are used for different things,&lt;BR /&gt;
in youre case X670 has 10 slices and sum of 10 slices rules is 2048. &lt;BR /&gt;
&lt;BR /&gt;
You have in use:&lt;BR /&gt;
Stage: INGRESS&lt;BR /&gt;
Slices: Used: 9 Available: 1&lt;BR /&gt;
&lt;BR /&gt;
I don't know your config and ACL's, &lt;BR /&gt;
but "Error: ACL install operation failed - slice hardware full for vlan Curriculum_Server, port *" could mean:&lt;BR /&gt;
&lt;BR /&gt;
1) That some functions need for it own use slices and cannot share it with others&lt;BR /&gt;
&lt;BR /&gt;
You can check that when you remove some of ACL's, &lt;BR /&gt;
then show access-list usage acl-slice port 1 what sliceses are free.&lt;BR /&gt;
And then add this accesslist C_S, then check slices usage&lt;BR /&gt;
&lt;BR /&gt;
2) Sometimes the solution is to write acl's in file in a different order or/and&lt;BR /&gt;
add policy it in diffrent order.&lt;BR /&gt;
&lt;BR /&gt;
I had some time ago similar problem with X250e I don't remeber in what soft that was.&lt;BR /&gt;
When the switch reboot it add some acl policy for vlans then add ip-security things like dhp-snooping &lt;BR /&gt;
and arpvalidation. In logs I saw ACL install operation failed ...&lt;BR /&gt;
But when I removed all ACL's, and first add ip-security things then the ACL for vlan &lt;BR /&gt;
it works with no error.&lt;BR /&gt;
&lt;BR /&gt;
3) Maybe a firmware bug ? What firmware you have ?&lt;BR /&gt;
&lt;BR /&gt;
--&lt;BR /&gt;
Jarek&lt;BR /&gt;
&lt;BR /&gt;
  (from Jaroslaw_Kasjaniuk)</description>
    <pubDate>Wed, 08 Jan 2014 06:04:00 GMT</pubDate>
    <dc:creator>EtherNation_Use</dc:creator>
    <dc:date>2014-01-08T06:04:00Z</dc:date>
    <item>
      <title>ACL slices</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/acl-slices/m-p/28209#M4291</link>
      <description>Create Date: Aug 23 2013 12:39PM&lt;BR /&gt;
&lt;BR /&gt;
hi&lt;BR /&gt;
&lt;BR /&gt;
i am trying to put acls on our core switch to prevent access between certain vlans. but run out of slices quickly.&lt;BR /&gt;
&lt;BR /&gt;
i don't understand slices or how it is calculated???&lt;BR /&gt;
&lt;BR /&gt;
* X670-48x.9 # show access-list usage acl-slice port 1&lt;BR /&gt;
Ports 1-48&lt;BR /&gt;
Stage: INGRESS&lt;BR /&gt;
Slices:          Used: 9  Available: 1&lt;BR /&gt;
Slice 0 Rules:   Used: 0  Available: 128&lt;BR /&gt;
Slice 1 Rules:   Used: 3  Available: 125 user/other&lt;BR /&gt;
Slice 2 Rules:   Used: 20  Available: 108 system&lt;BR /&gt;
Slice 3 Rules:   Used: 6  Available: 122 system&lt;BR /&gt;
Slice 4 Rules:   Used: 3  Available: 253 user/other&lt;BR /&gt;
Slice 5 Rules:   Used: 6  Available: 250 user/other&lt;BR /&gt;
Slice 6 Rules:   Used: 3  Available: 253 user/other&lt;BR /&gt;
Slice 7 Rules:   Used: 6  Available: 250 user/other&lt;BR /&gt;
Slice 8 Rules:   Used: 3  Available: 253 user/other&lt;BR /&gt;
Slice 9 Rules:   Used: 8  Available: 248 user/other&lt;BR /&gt;
Stage: EGRESS&lt;BR /&gt;
Slices:          Used: 0  Available: 4&lt;BR /&gt;
Slice 0 Rules:   Used: 0  Available: 256&lt;BR /&gt;
Slice 1 Rules:   Used: 0  Available: 256&lt;BR /&gt;
Slice 2 Rules:   Used: 0  Available: 256&lt;BR /&gt;
Slice 3 Rules:   Used: 0  Available: 256&lt;BR /&gt;
Stage: LOOKUP&lt;BR /&gt;
Slices:          Used: 1  Available: 3&lt;BR /&gt;
Slice 0 Rules:   Used: 0  Available: 256&lt;BR /&gt;
Slice 1 Rules:   Used: 0  Available: 256&lt;BR /&gt;
Slice 2 Rules:   Used: 0  Available: 256&lt;BR /&gt;
Slice 3 Rules:   Used: 49  Available: 207&lt;BR /&gt;
Stage: EXTERNAL&lt;BR /&gt;
Slices:          Used: 0  Available: 0&lt;BR /&gt;
* X670-48x.10 #&lt;BR /&gt;
  (from Conrad_Jones)</description>
      <pubDate>Wed, 08 Jan 2014 06:04:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/acl-slices/m-p/28209#M4291</guid>
      <dc:creator>EtherNation_Use</dc:creator>
      <dc:date>2014-01-08T06:04:00Z</dc:date>
    </item>
    <item>
      <title>RE: ACL slices</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/acl-slices/m-p/28210#M4292</link>
      <description>Create Date: Aug 23 2013 12:58PM&lt;BR /&gt;
&lt;BR /&gt;
Hi, &lt;BR /&gt;
&lt;BR /&gt;
I think you can find answer to your question in concept guide:&lt;BR /&gt;
Chapter ACL -&amp;gt; ACL Mechanisms - 681 &lt;BR /&gt;
&lt;BR /&gt;
Jarek  (from Jaroslaw_Kasjaniuk)</description>
      <pubDate>Wed, 08 Jan 2014 06:04:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/acl-slices/m-p/28210#M4292</guid>
      <dc:creator>EtherNation_Use</dc:creator>
      <dc:date>2014-01-08T06:04:00Z</dc:date>
    </item>
    <item>
      <title>RE: ACL slices</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/acl-slices/m-p/28211#M4293</link>
      <description>Create Date: Aug 23 2013  1:08PM&lt;BR /&gt;
&lt;BR /&gt;
Vlan Name    Port   Policy Name          Dir      Rules  Dyn Rules&lt;BR /&gt;
===================================================================&lt;BR /&gt;
Internet     *      Internet             ingress  9      0&lt;BR /&gt;
dmz          *      DMZ                  ingress  9      0&lt;BR /&gt;
dmz          1                           ingress  0      2&lt;BR /&gt;
dmz          2                           ingress  0      2&lt;BR /&gt;
dmz          3                           ingress  0      2&lt;BR /&gt;
dmz          45                          ingress  0      2&lt;BR /&gt;
dmz          46                          ingress  0      2&lt;BR /&gt;
dmz          47                          ingress  0      2&lt;BR /&gt;
dmz          48                          ingress  0      2&lt;BR /&gt;
Admin_Server *      A_S                  ingress  9      0&lt;BR /&gt;
&lt;BR /&gt;
* X670-48x.2 # configure access-list C_S vlan Curriculum&lt;BR /&gt;
  &lt;VLANNAME&gt;      vlan name&lt;BR /&gt;
    "Curriculum"  "Curriculum_PC"  "Curriculum_Printer"  "Curriculum_Server"&lt;BR /&gt;
* X670-48x.2 # configure access-list C_S vlan "Curriculum_Server"&lt;BR /&gt;
&lt;BR /&gt;
Error: ACL install operation failed - slice hardware full for vlan Curriculum_Se&lt;BR /&gt;
rver, port *&lt;BR /&gt;
* X670-48x.3 #&lt;BR /&gt;
&lt;BR /&gt;
&lt;BR /&gt;
&lt;BR /&gt;
Apologies i have read that, i don't think I'm approaching any where near 2048 ingress rules.&lt;BR /&gt;
&lt;BR /&gt;
Each group of 48 ports has 10 slices; the first 4 (0-3) slices hold 128 ingress rules each, and the last&lt;BR /&gt;
6 (4-9) slices hold 256 ingress rules each, which adds up to 2048 ingress rules.&lt;BR /&gt;
&lt;BR /&gt;
  (from Conrad_Jones)&lt;/VLANNAME&gt;</description>
      <pubDate>Wed, 08 Jan 2014 06:04:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/acl-slices/m-p/28211#M4293</guid>
      <dc:creator>EtherNation_Use</dc:creator>
      <dc:date>2014-01-08T06:04:00Z</dc:date>
    </item>
    <item>
      <title>RE: ACL slices</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/acl-slices/m-p/28212#M4294</link>
      <description>Create Date: Aug 23 2013  5:50PM&lt;BR /&gt;
&lt;BR /&gt;
For my knowledge different slices are used for different things,&lt;BR /&gt;
in youre case X670 has 10 slices and sum of 10 slices rules is 2048. &lt;BR /&gt;
&lt;BR /&gt;
You have in use:&lt;BR /&gt;
Stage: INGRESS&lt;BR /&gt;
Slices: Used: 9 Available: 1&lt;BR /&gt;
&lt;BR /&gt;
I don't know your config and ACL's, &lt;BR /&gt;
but "Error: ACL install operation failed - slice hardware full for vlan Curriculum_Server, port *" could mean:&lt;BR /&gt;
&lt;BR /&gt;
1) That some functions need for it own use slices and cannot share it with others&lt;BR /&gt;
&lt;BR /&gt;
You can check that when you remove some of ACL's, &lt;BR /&gt;
then show access-list usage acl-slice port 1 what sliceses are free.&lt;BR /&gt;
And then add this accesslist C_S, then check slices usage&lt;BR /&gt;
&lt;BR /&gt;
2) Sometimes the solution is to write acl's in file in a different order or/and&lt;BR /&gt;
add policy it in diffrent order.&lt;BR /&gt;
&lt;BR /&gt;
I had some time ago similar problem with X250e I don't remeber in what soft that was.&lt;BR /&gt;
When the switch reboot it add some acl policy for vlans then add ip-security things like dhp-snooping &lt;BR /&gt;
and arpvalidation. In logs I saw ACL install operation failed ...&lt;BR /&gt;
But when I removed all ACL's, and first add ip-security things then the ACL for vlan &lt;BR /&gt;
it works with no error.&lt;BR /&gt;
&lt;BR /&gt;
3) Maybe a firmware bug ? What firmware you have ?&lt;BR /&gt;
&lt;BR /&gt;
--&lt;BR /&gt;
Jarek&lt;BR /&gt;
&lt;BR /&gt;
  (from Jaroslaw_Kasjaniuk)</description>
      <pubDate>Wed, 08 Jan 2014 06:04:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/acl-slices/m-p/28212#M4294</guid>
      <dc:creator>EtherNation_Use</dc:creator>
      <dc:date>2014-01-08T06:04:00Z</dc:date>
    </item>
    <item>
      <title>RE: ACL slices</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/acl-slices/m-p/28213#M4295</link>
      <description>Create Date: Aug 23 2013  6:54PM&lt;BR /&gt;
&lt;BR /&gt;
i've got loads of VRRP going on on that switch and some dhcp snooping but the way i read the pdf they used the system slice not the user/other ? not sure here though&lt;BR /&gt;
&lt;BR /&gt;
firmware, i updated today to the latest xos and it didn't make a difference, i will check firmware versions on tuesday as i have left the site now. &lt;BR /&gt;
&lt;BR /&gt;
i may backup the config and try reseting the whole switch though i'd rather not   (from Conrad_Jones)</description>
      <pubDate>Wed, 08 Jan 2014 06:04:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/acl-slices/m-p/28213#M4295</guid>
      <dc:creator>EtherNation_Use</dc:creator>
      <dc:date>2014-01-08T06:04:00Z</dc:date>
    </item>
  </channel>
</rss>

