Wired Intelligent Edge (Campus Switching and Routing)

 View Only
last person joined: one year ago 

Bring performance and reliability to your network with the HPE Aruba Networking Core, Aggregation, and Access layer switches. Discuss the latest features and functionality of HPE Aruba Networking switching devices, and find ways to improve security across your network.

How can I tell how many ACL's I can have on my Aruba switch? 

Oct 03, 2018 11:12 AM

Requirement:

To see a comprehensive view of how many ACL's you can have you can use the following command:

SWITCH# show access-list resource

 

 

 

 



Solution:

SWITCH# show access-list resource

HP-Switch-5412Rzl2# show access-list resource

 Resource usage in Policy Enforcement Engine


 Ingress Policy Enforcement Engine Rules


 Resource usage in Policy Enforcement Engine

               |   Rules   |  Rules Used
         Slots | Available | ACL | QoS | IDM |  VT | Mirr | PBR |  OF  | Other |
 --------------+-----------+-----+-----+-----+-----+------+-----+------+-------|
   A           |      8166 |   0 |   0 |   0 |   0 |    0 |   0 |    0 |     6 |
   B           |      8166 |   0 |   0 |   0 |   0 |    0 |   0 |    0 |     6 |


 Ingress Policy Enforcement Engine Meters

               |   Meters  |  Meters Used
         Slots | Available | ACL | QoS | IDM |  VT | Mirr | PBR |  OF  | Other |
 --------------+-----------+-----+-----+-----+-----+------+-----+------+-------|
   A           |      2046 |     |   0 |   0 |   0 |      |     |    0 |     0 |
   B           |      2046 |     |   0 |   0 |   0 |      |     |    0 |     0 |


 Ingress Policy Enforcement Engine Port Ranges

               |Application|
               |Port Ranges|  Application Port Ranges Used
         Slots | Available | ACL | QoS | IDM |  VT | Mirr | PBR |  OF  | Other |
 --------------+-----------+-----+-----+-----+-----+------+-----+------+-------|
   A           |        60 |   0 |   0 |   0 |     |    0 |   0 |    0 |     0 |
   B           |        60 |   0 |   0 |   0 |     |    0 |   0 |    0 |     0 |


 Ingress Policy Enforcement Engine PBR Resources

               |    PBR    |
               | Next-hops |  PBR Next-hops Used
         Slots | Available | ACL | QoS | IDM |  VT | Mirr | PBR |  OF  | Other |
 --------------+-----------+-----+-----+-----+-----+------+-----+------+-------|
   A           |      1024 |     |     |     |     |      |   0 |      |     0 |
   B           |      1024 |     |     |     |     |      |   0 |      |     0 |

 4 of 32 Policy Engine management resources used.

 Key:
 ACL = Access Control Lists
 QoS = Device & Application Port Priority, QoS Policies, ICMP rate limits
 IDM = Identity Driven Management
 VT  = Virus Throttling blocks
 Mirr = Mirror Policies, Remote Intelligent Mirror endpoints
 PBR = Policy Based Routing Policies
 OF = OpenFlow
 Other = Management VLAN, DHCP Snooping, ARP Protection, Jumbo IP-MTU,
         RA Guard, Control Plane Protection, Service Tunnel, ND Snooping, UWW,
         mDNS, tunneled-node-server, copp, ICMP rate-limit,
         Unknown Unicast rate-limit.

 Resource usage includes resources actually in use, or reserved for future
 use by the listed feature.  Internal dedicated-purpose resources, such as
 port bandwidth limits or VLAN QoS priority, are not included.



Configuration:

SWITCH# show access-list resource



Verification

 

HP-Switch-5412Rzl2# show access-list resource

 Resource usage in Policy Enforcement Engine


 Ingress Policy Enforcement Engine Rules


 Resource usage in Policy Enforcement Engine

               |   Rules   |  Rules Used
         Slots | Available | ACL | QoS | IDM |  VT | Mirr | PBR |  OF  | Other |
 --------------+-----------+-----+-----+-----+-----+------+-----+------+-------|
   A           |      8166 |   0 |   0 |   0 |   0 |    0 |   0 |    0 |     6 |
   B           |      8166 |   0 |   0 |   0 |   0 |    0 |   0 |    0 |     6 |


 Ingress Policy Enforcement Engine Meters

               |   Meters  |  Meters Used
         Slots | Available | ACL | QoS | IDM |  VT | Mirr | PBR |  OF  | Other |
 --------------+-----------+-----+-----+-----+-----+------+-----+------+-------|
   A           |      2046 |     |   0 |   0 |   0 |      |     |    0 |     0 |
   B           |      2046 |     |   0 |   0 |   0 |      |     |    0 |     0 |


 Ingress Policy Enforcement Engine Port Ranges

               |Application|
               |Port Ranges|  Application Port Ranges Used
         Slots | Available | ACL | QoS | IDM |  VT | Mirr | PBR |  OF  | Other |
 --------------+-----------+-----+-----+-----+-----+------+-----+------+-------|
   A           |        60 |   0 |   0 |   0 |     |    0 |   0 |    0 |     0 |
   B           |        60 |   0 |   0 |   0 |     |    0 |   0 |    0 |     0 |


 Ingress Policy Enforcement Engine PBR Resources

               |    PBR    |
               | Next-hops |  PBR Next-hops Used
         Slots | Available | ACL | QoS | IDM |  VT | Mirr | PBR |  OF  | Other |
 --------------+-----------+-----+-----+-----+-----+------+-----+------+-------|
   A           |      1024 |     |     |     |     |      |   0 |      |     0 |
   B           |      1024 |     |     |     |     |      |   0 |      |     0 |

 4 of 32 Policy Engine management resources used.

 Key:
 ACL = Access Control Lists
 QoS = Device & Application Port Priority, QoS Policies, ICMP rate limits
 IDM = Identity Driven Management
 VT  = Virus Throttling blocks
 Mirr = Mirror Policies, Remote Intelligent Mirror endpoints
 PBR = Policy Based Routing Policies
 OF = OpenFlow
 Other = Management VLAN, DHCP Snooping, ARP Protection, Jumbo IP-MTU,
         RA Guard, Control Plane Protection, Service Tunnel, ND Snooping, UWW,
         mDNS, tunneled-node-server, copp, ICMP rate-limit,
         Unknown Unicast rate-limit.

 Resource usage includes resources actually in use, or reserved for future
 use by the listed feature.  Internal dedicated-purpose resources, such as
 port bandwidth limits or VLAN QoS priority, are not included.

Statistics
0 Favorited
3 Views
0 Files
0 Shares
0 Downloads

Related Entries and Links

No Related Resource entered.