cancel
Showing results for 
Search instead for 
Did you mean: 

7100-Series / ACL / Access Control List / Limitations

7100-Series / ACL / Access Control List / Limitations

networks
New Contributor
We want to transfer a large ACL from a DFE module (with Advanced Licence) to an 7100 (about 300 entries). We can only enter 171 lines, then we're done.

The "show limits" command displays:

Chassis limits:
Application Limit In use Entry size Total Memory
-------------------------------- --------- --------- ------------ ------------
access-lists 256 9 125K 31.3M
access-list-entries 1000 171 160B 156.4K
access-list-entries-per-list 1000 - - -
applied-access-lists 1552 0 110B 165.5K
applied-ipv4-in 256 0 - -
applied-ipv4-out 256 0 - -
applied-ipv6-in 256 0 - -
applied-ipv6-out 256 0 - -
applied-l2-in 256 0 - -
applied-l2-out 256 0 - -

The "show limits resource-profile -verbose" command displays:

Resource Profile: router1
Authenticated Users = 512
MAC Rules = 0
IPV6 Rules = 0
IPV4 Rules = 249
L2 Rules = 175
IPV6 Ingress ACL = 128
IPV6 PBR = 0
IPV4 Ingress ACL = 128
IPV4 PBR = 128
L2 Ingress ACL = 0
IPV6 Egress ACL = 256
IPV4 Egress ACL = 256
L2 Egress ACL = 0

How can we solve the problem (more accepted entries in the ACL)?
26 REPLIES 26

Careno__Ryan
Extreme Employee
I created 10 access-lists with 25 entries in each, however I won't be able to apply all of these to interfaces since it's exceeding the limit of 128 inbound rules applied.

ip access-list extended number1 permit ip host 1.1.1.1 host 1.1.1.1
permit ip host 1.1.1.1 host 1.1.1.2
permit ip host 1.1.1.1 host 1.1.1.3
permit ip host 1.1.1.1 host 1.1.1.4
permit ip host 1.1.1.1 host 1.1.1.5
permit ip host 1.1.1.1 host 1.1.1.6
permit ip host 1.1.1.1 host 1.1.1.7
permit ip host 1.1.1.1 host 1.1.1.8
permit ip host 1.1.1.1 host 1.1.1.9
permit ip host 1.1.1.1 host 1.1.1.10
permit ip host 1.1.1.1 host 1.1.1.11
permit ip host 1.1.1.1 host 1.1.1.12
permit ip host 1.1.1.1 host 1.1.1.13
permit ip host 1.1.1.1 host 1.1.1.14
permit ip host 1.1.1.1 host 1.1.1.15
permit ip host 1.1.1.1 host 1.1.1.16
permit ip host 1.1.1.1 host 1.1.1.17
permit ip host 1.1.1.1 host 1.1.1.18
permit ip host 1.1.1.1 host 1.1.1.19
permit ip host 1.1.1.1 host 1.1.1.20
permit ip host 1.1.1.1 host 1.1.1.21
permit ip host 1.1.1.1 host 1.1.1.22
permit ip host 1.1.1.1 host 1.1.1.23
permit ip host 1.1.1.1 host 1.1.1.24
permit ip any any
exit
ip access-list extended number10
permit ip host 1.1.1.1 host 1.1.1.1
permit ip host 1.1.1.1 host 1.1.1.2
permit ip host 1.1.1.1 host 1.1.1.3
permit ip host 1.1.1.1 host 1.1.1.4
permit ip host 1.1.1.1 host 1.1.1.5
permit ip host 1.1.1.1 host 1.1.1.6
permit ip host 1.1.1.1 host 1.1.1.7
permit ip host 1.1.1.1 host 1.1.1.8
permit ip host 1.1.1.1 host 1.1.1.9
permit ip host 1.1.1.1 host 1.1.1.10
permit ip host 1.1.1.1 host 1.1.1.11
permit ip host 1.1.1.1 host 1.1.1.12
permit ip host 1.1.1.1 host 1.1.1.13
permit ip host 1.1.1.1 host 1.1.1.14
permit ip host 1.1.1.1 host 1.1.1.15
permit ip host 1.1.1.1 host 1.1.1.16
permit ip host 1.1.1.1 host 1.1.1.17
permit ip host 1.1.1.1 host 1.1.1.18
permit ip host 1.1.1.1 host 1.1.1.19
permit ip host 1.1.1.1 host 1.1.1.20
permit ip host 1.1.1.1 host 1.1.1.21
permit ip host 1.1.1.1 host 1.1.1.22
permit ip host 1.1.1.1 host 1.1.1.23
permit ip host 1.1.1.1 host 1.1.1.24
permit ip any any
exit
ip access-list extended number2
permit ip host 1.1.1.1 host 1.1.1.1
permit ip host 1.1.1.1 host 1.1.1.2
permit ip host 1.1.1.1 host 1.1.1.3
permit ip host 1.1.1.1 host 1.1.1.4
permit ip host 1.1.1.1 host 1.1.1.5
permit ip host 1.1.1.1 host 1.1.1.6
permit ip host 1.1.1.1 host 1.1.1.7
permit ip host 1.1.1.1 host 1.1.1.8
permit ip host 1.1.1.1 host 1.1.1.9
permit ip host 1.1.1.1 host 1.1.1.10
permit ip host 1.1.1.1 host 1.1.1.11
permit ip host 1.1.1.1 host 1.1.1.12
permit ip host 1.1.1.1 host 1.1.1.13
permit ip host 1.1.1.1 host 1.1.1.14
permit ip host 1.1.1.1 host 1.1.1.15
permit ip host 1.1.1.1 host 1.1.1.16
permit ip host 1.1.1.1 host 1.1.1.17
permit ip host 1.1.1.1 host 1.1.1.18
permit ip host 1.1.1.1 host 1.1.1.19
permit ip host 1.1.1.1 host 1.1.1.20
permit ip host 1.1.1.1 host 1.1.1.21
permit ip host 1.1.1.1 host 1.1.1.22
permit ip host 1.1.1.1 host 1.1.1.23
permit ip host 1.1.1.1 host 1.1.1.24
permit ip any any
exit
ip access-list extended number3
permit ip host 1.1.1.1 host 1.1.1.1
permit ip host 1.1.1.1 host 1.1.1.2
permit ip host 1.1.1.1 host 1.1.1.3
permit ip host 1.1.1.1 host 1.1.1.4
permit ip host 1.1.1.1 host 1.1.1.5
permit ip host 1.1.1.1 host 1.1.1.6
permit ip host 1.1.1.1 host 1.1.1.7
permit ip host 1.1.1.1 host 1.1.1.8
permit ip host 1.1.1.1 host 1.1.1.9
permit ip host 1.1.1.1 host 1.1.1.10
permit ip host 1.1.1.1 host 1.1.1.11
permit ip host 1.1.1.1 host 1.1.1.12
permit ip host 1.1.1.1 host 1.1.1.13
permit ip host 1.1.1.1 host 1.1.1.14
permit ip host 1.1.1.1 host 1.1.1.15
permit ip host 1.1.1.1 host 1.1.1.16
permit ip host 1.1.1.1 host 1.1.1.17
permit ip host 1.1.1.1 host 1.1.1.18
permit ip host 1.1.1.1 host 1.1.1.19
permit ip host 1.1.1.1 host 1.1.1.20
permit ip host 1.1.1.1 host 1.1.1.21
permit ip host 1.1.1.1 host 1.1.1.22
permit ip host 1.1.1.1 host 1.1.1.23
permit ip host 1.1.1.1 host 1.1.1.24
permit ip any any
exit
ip access-list extended number4
permit ip host 1.1.1.1 host 1.1.1.1
permit ip host 1.1.1.1 host 1.1.1.2
permit ip host 1.1.1.1 host 1.1.1.3
permit ip host 1.1.1.1 host 1.1.1.4
permit ip host 1.1.1.1 host 1.1.1.5
permit ip host 1.1.1.1 host 1.1.1.6
permit ip host 1.1.1.1 host 1.1.1.7
permit ip host 1.1.1.1 host 1.1.1.8
permit ip host 1.1.1.1 host 1.1.1.9
permit ip host 1.1.1.1 host 1.1.1.10
permit ip host 1.1.1.1 host 1.1.1.11
permit ip host 1.1.1.1 host 1.1.1.12
permit ip host 1.1.1.1 host 1.1.1.13
permit ip host 1.1.1.1 host 1.1.1.14
permit ip host 1.1.1.1 host 1.1.1.15
permit ip host 1.1.1.1 host 1.1.1.16
permit ip host 1.1.1.1 host 1.1.1.17
permit ip host 1.1.1.1 host 1.1.1.18
permit ip host 1.1.1.1 host 1.1.1.19
permit ip host 1.1.1.1 host 1.1.1.20
permit ip host 1.1.1.1 host 1.1.1.21
permit ip host 1.1.1.1 host 1.1.1.22
permit ip host 1.1.1.1 host 1.1.1.23
permit ip host 1.1.1.1 host 1.1.1.24
permit ip any any
exit
ip access-list extended number5
permit ip host 1.1.1.1 host 1.1.1.1
permit ip host 1.1.1.1 host 1.1.1.2
permit ip host 1.1.1.1 host 1.1.1.3
permit ip host 1.1.1.1 host 1.1.1.4
permit ip host 1.1.1.1 host 1.1.1.5
permit ip host 1.1.1.1 host 1.1.1.6
permit ip host 1.1.1.1 host 1.1.1.7
permit ip host 1.1.1.1 host 1.1.1.8
permit ip host 1.1.1.1 host 1.1.1.9
permit ip host 1.1.1.1 host 1.1.1.10
permit ip host 1.1.1.1 host 1.1.1.11
permit ip host 1.1.1.1 host 1.1.1.12
permit ip host 1.1.1.1 host 1.1.1.13
permit ip host 1.1.1.1 host 1.1.1.14
permit ip host 1.1.1.1 host 1.1.1.15
permit ip host 1.1.1.1 host 1.1.1.16
permit ip host 1.1.1.1 host 1.1.1.17
permit ip host 1.1.1.1 host 1.1.1.18
permit ip host 1.1.1.1 host 1.1.1.19
permit ip host 1.1.1.1 host 1.1.1.20
permit ip host 1.1.1.1 host 1.1.1.21
permit ip host 1.1.1.1 host 1.1.1.22
permit ip host 1.1.1.1 host 1.1.1.23
permit ip host 1.1.1.1 host 1.1.1.24
permit ip any any
exit
ip access-list extended number6
permit ip host 1.1.1.1 host 1.1.1.1
permit ip host 1.1.1.1 host 1.1.1.2
permit ip host 1.1.1.1 host 1.1.1.3
permit ip host 1.1.1.1 host 1.1.1.4
permit ip host 1.1.1.1 host 1.1.1.5
permit ip host 1.1.1.1 host 1.1.1.6
permit ip host 1.1.1.1 host 1.1.1.7
permit ip host 1.1.1.1 host 1.1.1.8
permit ip host 1.1.1.1 host 1.1.1.9
permit ip host 1.1.1.1 host 1.1.1.10
permit ip host 1.1.1.1 host 1.1.1.11
permit ip host 1.1.1.1 host 1.1.1.12
permit ip host 1.1.1.1 host 1.1.1.13
permit ip host 1.1.1.1 host 1.1.1.14
permit ip host 1.1.1.1 host 1.1.1.15
permit ip host 1.1.1.1 host 1.1.1.16
permit ip host 1.1.1.1 host 1.1.1.17
permit ip host 1.1.1.1 host 1.1.1.18
permit ip host 1.1.1.1 host 1.1.1.19
permit ip host 1.1.1.1 host 1.1.1.20
permit ip host 1.1.1.1 host 1.1.1.21
permit ip host 1.1.1.1 host 1.1.1.22
permit ip host 1.1.1.1 host 1.1.1.23
permit ip host 1.1.1.1 host 1.1.1.24
permit ip any any
exit
ip access-list extended number7
permit ip host 1.1.1.1 host 1.1.1.1
permit ip host 1.1.1.1 host 1.1.1.2
permit ip host 1.1.1.1 host 1.1.1.3
permit ip host 1.1.1.1 host 1.1.1.4
permit ip host 1.1.1.1 host 1.1.1.5
permit ip host 1.1.1.1 host 1.1.1.6
permit ip host 1.1.1.1 host 1.1.1.7
permit ip host 1.1.1.1 host 1.1.1.8
permit ip host 1.1.1.1 host 1.1.1.9
permit ip host 1.1.1.1 host 1.1.1.10
permit ip host 1.1.1.1 host 1.1.1.11
permit ip host 1.1.1.1 host 1.1.1.12
permit ip host 1.1.1.1 host 1.1.1.13
permit ip host 1.1.1.1 host 1.1.1.14
permit ip host 1.1.1.1 host 1.1.1.15
permit ip host 1.1.1.1 host 1.1.1.16
permit ip host 1.1.1.1 host 1.1.1.17
permit ip host 1.1.1.1 host 1.1.1.18
permit ip host 1.1.1.1 host 1.1.1.19
permit ip host 1.1.1.1 host 1.1.1.20
permit ip host 1.1.1.1 host 1.1.1.21
permit ip host 1.1.1.1 host 1.1.1.22
permit ip host 1.1.1.1 host 1.1.1.23
permit ip host 1.1.1.1 host 1.1.1.24
permit ip any any
exit
ip access-list extended number8
permit ip host 1.1.1.1 host 1.1.1.1
permit ip host 1.1.1.1 host 1.1.1.2
permit ip host 1.1.1.1 host 1.1.1.3
permit ip host 1.1.1.1 host 1.1.1.4
permit ip host 1.1.1.1 host 1.1.1.5
permit ip host 1.1.1.1 host 1.1.1.6
permit ip host 1.1.1.1 host 1.1.1.7
permit ip host 1.1.1.1 host 1.1.1.8
permit ip host 1.1.1.1 host 1.1.1.9
permit ip host 1.1.1.1 host 1.1.1.10
permit ip host 1.1.1.1 host 1.1.1.11
permit ip host 1.1.1.1 host 1.1.1.12
permit ip host 1.1.1.1 host 1.1.1.13
permit ip host 1.1.1.1 host 1.1.1.14
permit ip host 1.1.1.1 host 1.1.1.15
permit ip host 1.1.1.1 host 1.1.1.16
permit ip host 1.1.1.1 host 1.1.1.17
permit ip host 1.1.1.1 host 1.1.1.18
permit ip host 1.1.1.1 host 1.1.1.19
permit ip host 1.1.1.1 host 1.1.1.20
permit ip host 1.1.1.1 host 1.1.1.21
permit ip host 1.1.1.1 host 1.1.1.22
permit ip host 1.1.1.1 host 1.1.1.23
permit ip host 1.1.1.1 host 1.1.1.24
permit ip any any
exit
ip access-list extended number9
permit ip host 1.1.1.1 host 1.1.1.1
permit ip host 1.1.1.1 host 1.1.1.2
permit ip host 1.1.1.1 host 1.1.1.3
permit ip host 1.1.1.1 host 1.1.1.4
permit ip host 1.1.1.1 host 1.1.1.5
permit ip host 1.1.1.1 host 1.1.1.6
permit ip host 1.1.1.1 host 1.1.1.7
permit ip host 1.1.1.1 host 1.1.1.8
permit ip host 1.1.1.1 host 1.1.1.9
permit ip host 1.1.1.1 host 1.1.1.10
permit ip host 1.1.1.1 host 1.1.1.11
permit ip host 1.1.1.1 host 1.1.1.12
permit ip host 1.1.1.1 host 1.1.1.13
permit ip host 1.1.1.1 host 1.1.1.14
permit ip host 1.1.1.1 host 1.1.1.15
permit ip host 1.1.1.1 host 1.1.1.16
permit ip host 1.1.1.1 host 1.1.1.17
permit ip host 1.1.1.1 host 1.1.1.18
permit ip host 1.1.1.1 host 1.1.1.19
permit ip host 1.1.1.1 host 1.1.1.20
permit ip host 1.1.1.1 host 1.1.1.21
permit ip host 1.1.1.1 host 1.1.1.22
permit ip host 1.1.1.1 host 1.1.1.23
permit ip host 1.1.1.1 host 1.1.1.24
permit ip any any
exit

networks
New Contributor
and when you create 10 access-lists with round about 25 access-list-entries each?

Careno__Ryan
Extreme Employee
I created an ACL that has 200 Rules, however you can only have 128 rules applied at any given time, so would have to delete rule# 128-200 to get it to apply to an interface.

I would suggest opening a case with GTAC so we can review configurations and try to assist getting a working configuration.

Ryan

networks
New Contributor
with Profile "router1" IPV4 Egress ACL means 249 ACLs? but why we cannot use more than 180?
GTM-P2G8KFN