cancel
Showing results for 
Search instead for 
Did you mean: 

7100-Series / ACL / Access Control List / Limitations

7100-Series / ACL / Access Control List / Limitations

networks
New Contributor
We want to transfer a large ACL from a DFE module (with Advanced Licence) to an 7100 (about 300 entries). We can only enter 171 lines, then we're done.

The "show limits" command displays:

Chassis limits:
Application Limit In use Entry size Total Memory
-------------------------------- --------- --------- ------------ ------------
access-lists 256 9 125K 31.3M
access-list-entries 1000 171 160B 156.4K
access-list-entries-per-list 1000 - - -
applied-access-lists 1552 0 110B 165.5K
applied-ipv4-in 256 0 - -
applied-ipv4-out 256 0 - -
applied-ipv6-in 256 0 - -
applied-ipv6-out 256 0 - -
applied-l2-in 256 0 - -
applied-l2-out 256 0 - -

The "show limits resource-profile -verbose" command displays:

Resource Profile: router1
Authenticated Users = 512
MAC Rules = 0
IPV6 Rules = 0
IPV4 Rules = 249
L2 Rules = 175
IPV6 Ingress ACL = 128
IPV6 PBR = 0
IPV4 Ingress ACL = 128
IPV4 PBR = 128
L2 Ingress ACL = 0
IPV6 Egress ACL = 256
IPV4 Egress ACL = 256
L2 Egress ACL = 0

How can we solve the problem (more accepted entries in the ACL)?
26 REPLIES 26

networks
New Contributor
But why the "show" commands displays 249/1000 possible IPV4 rules and the configuration accepts only 171 rules?

That error is in the article I posted and caused by using an ACL with UDP port ranges.

these is the error message:

TOR(rw-config-intf-vlan.0.1001)->ip access-group 101 out

Apply access-group failed: Insufficient resources to apply access-group

Sorry for the issue, you might be encountering a limmitation other than the number of acl. I have one below as an example and am not saying it is your issue but it is an example.
https://gtacknowledge.extremenetworks.com/articles/Solution/7100-Series-Error-Apply-access-group-fai...

Do you get an error message or see an error inthe show logging buffer about the ACL?

Daniel_Coughlin
Extreme Employee
there is only the default and router1 profiles.

GTM-P2G8KFN