IP Addresses and Services Configuration Guide for Cisco 8000 Series Routers, IOS XR Releases

PDF

IP Addresses and Services Configuration Guide for Cisco 8000 Series Routers, IOS XR Releases

Hybrid ACLs

Want to summarize with AI?

Log in

This topic describes hybrid ACLs, also known as object-group ACLs on the Cisco 8000 Series Router, which simplify access control by grouping users, devices, or protocols into object groups and reducing the number of Access Control Entries (ACEs).


A hybrid ACL is an access control mechanism that

  • simplifies access control policies by grouping users, devices, or protocols into object groups

  • reduces the number of Access Control Entries (ACEs), making ACLs easier to manage and more readable, and

  • optimizes TCAM storage by using object-group ACLs instead of conventional ACLs, allowing compression levels for object-group ACLs and supporting up to 4000 ACEs per line card in the ingress direction.

The bit compression for OG-ACLs is a method that

  • enhances capability by expanding the compression result sizes from 24 bits to 26 bits for both IPv4 and IPv6 ingress OG-ACLs, and

  • supports longer lists of source or destination prefixes with variable lengths to address requirements such as wider compression results.

Table 1. Feature History Table

Feature Name

Release Information

Feature Description

Egress hybrid ACL support

Release 26.3.1

Introduced in this release on: Modular Systems (8800 [LC ASIC: K100])(select variants only*)

*This feature is supported on Cisco 88-LC1-48Y8F-EM line cards.

Viewing TCAM usage for source prefixes

Release 26.3.1

Introduced in this release on: Modular Systems (8800 [LC ASIC: K100])(select variants only*)

*This feature is supported on Cisco 88-LC1-48Y8F-EM line cards.

Viewing TCAM usage for source prefixes

Release 26.3.1

Introduced in this release on: Fixed Systems (8700 [ASIC: K100]) (select variants only*)

*This feature is supported on Cisco 8711-28H8F-M.

24 bit bincode support for egress object-group ACLs

Release 26.2.1

Introduced in this release on: Fixed Systems (8200 [ASIC: P100], 8700 [ASIC: P100]), 8010 [ASIC: A100]; Modular Systems (8800 [LC ASIC: P100])

You can now improve network policy granularity and control by supporting 24-bit bincode sizes for egress object-group ACLs.

This enhancement improves the efficiency of handling extended network object-groups and supports the inclusion of larger, more detailed prefix lists.

This feature introduces the hw-module profile tcam format og-compr-id-extension egress command.

Slice-Aware Prefix Programming for Egress Object-Group ACLs

Release 26.2.1

Introduced in this release on: Fixed Systems (8200 [ASIC: Q200, P100], 8700 [ASIC: P100, K100], 8010 [ASIC: A100]); Centralized Systems (8600 [ASIC:Q200]); Modular Systems (8800 [LC ASIC: Q200, P100])

This feature enhances hardware efficiency by programming Egress Object-Group ACL (OG-ACL) prefixes only on the active slices where an ACL is applied, rather than replicating them across all slices. Previously, prefixes were duplicated on every slice, leading to higher TCAM and HCAM usage and reduced performance. The software now automatically identifies and programs prefixes only for relevant slices, dynamically replicating them when new interfaces or bundle members are added. This optimization increases scalability for other hardware-based applications, supports both IPv4 and IPv6 OG-ACLs, and requires no additional configuration.

Egress hybrid ACL support

Release 26.1.1

Introduced in this release on: Centralized Systems (8400 [ASIC: K100]) (select variants only*)

*This feature is supported on Cisco 8404-SYS-D routers.

Viewing TCAM usage for source prefixes

Release 26.1.1

Introduced in this release on: Centralized Systems (8400 [ASIC: K100]) (select variants only*)

*This feature is supported on Cisco 8404-SYS-D routers.

Egress hybrid ACL support

Release 25.4.1

Introduced in this release on: Fixed Systems (8200 [ASIC: K100], 8010 [ASIC: A100])(select variants only*), 8700 [ASIC: K100])(select variants only*)

*This feature is supported on:

  • 8011-32Y8L2H2FH

  • 8011-12G12X4Y-A/D

P100-based ASICs now support a larger bincode size of 18 bits instead of 14 bits. This increase allows the forwarding pipeline to encode more feature states simultaneously, enabling support for complex egress processing scenarios such as hybrid egress ACL deployments.

Enhanced 26 bit compression for object-group ACLs

Release 25.2.1

Introduced in this release on: Fixed Systems (8200 [ASIC: P100], 8700 [ASIC: P100]); Modular Systems (8800 [LC ASIC: P100])

You can now improve network policy granularity and control by supporting 26-bit bincode sizes for both source and destination prefixes in ingress object-group ACLs.

This enhancement improves the efficiency of handling extended network object-groups and supports the inclusion of larger, more detailed prefix lists.

This feature introduces the hw-module profile tcam format og-compr-id-extension command.

Egress Hybrid ACL Support

Release 25.1.1

Introduced in this release on: Fixed Systems (8700 [ASIC: K100], 8010 [ASIC: A100])(select variants only*)

Compression levels for object-group ACLs, also known as hybrid ACLs, can now be applied to egress traffic. This ACL compression optimizes the usage of TCAM space, allowing the router to support additional ACLs or features and ensuring efficient utilization of the limited TCAM resources available.

This feature is supported on:

  • 8712-MOD-M

  • 8011-4G24Y4H-I

Viewing TCAM usage for source prefixes

Release 25.1.1

Introduced in this release on: Fixed Systems (8200 [ASIC: Q200], Centralized Systems (8600 [ASIC:Q200]); Modular Systems (8800 [LC ASIC: Q200])

This features ensures that source prefixes of the egress hybrid ACLs are now stored in a separate TCAM interface, enabling accurate resource monitoring and tracking. Use the show controllers npu resource egressacltcam location command to view the TCAM usage.

In earlier releases, while the destination prefixes of the hybrid ACLs were stored in the ACL TCAM interface, the source prefixes were unreported, making it challenging to monitor their accurate TCAM resource usage.

Enhanced 24 bit compression for object-group ACLs

Release 25.1.1

Introduced in this release on: Fixed Systems (8200 [ASIC: Q200, P100], 8700 [ASIC: P100, K100], 8010 [ASIC: A100]); Centralized Systems (8600 [ASIC:Q200]); Modular Systems (8800 [LC ASIC: Q100, Q200, P100])

This release introduces support for more efficient handling of extended network object-groups by expanding source and destination compression results.

This is achieved by enabling support for 24 bit bincode sizes for both source and destination prefixes in the ingress object-group ACLs, which accommodates larger and more detailed prefix lists for supporting more complex network object-groups and configurations.

Prior to release 25.1.1, this capability was limited to 20 bit compression for both source and destination prefixes, restricting the length and variability of network prefixes that could be managed within ACLs.

Egress Hybrid ACL Support

Release 24.4.1

Introduced in this release on: Fixed Systems (8200 [ASIC: P100], 8700 [ASIC: P100])(select variants only*); Modular Systems (8800 [LC ASIC: P100])(select variants only*)

*This feature is supported on:

  • 8212-48FH-M

  • 8711-32FH-M

  • 88-LC1-36EH

  • 88-LC1-12TH24FH-E

  • 88-LC1-52Y8H-EM

Egress Hybrid ACL Support

Release 7.10.1

From this release onwards, you can apply compression levels for object-group ACLs, also known as hybrid ACLs, at the egress traffic. Because ACL compression optimizes TCAM space usage, it enables the router to accommodate additional ACLs or features.

This feature is supported only on Q200 ASIC based systems.

Hybrid ACLs

Release 7.3.1

You can apply compression levels for object-group ACLs and attach up to 4000 ACEs per line card in the ingress direction. This leads to optimal TCAM space usage and resources utilization.


Benefits of hybrid ACLs

Hybrid ACLs provide these benefits:

  • streamline access control by grouping users, devices, or protocols,

  • enhance scalability and efficiency by reducing the number of ACEs per ACL, and

  • support larger bincode sizes to accommodate longer and more detailed prefix lists.

Streamline access control

Hybrid ACLs or object-group ACLs classifies users, devices, or protocols into groups so that you can have a group-level access control policy. Instead of specifying individual IP addresses, protocols, and port numbers in multiple ACEs, you can specify just the object group in a single ACL.

Enhance scalability and efficiency

This feature is very beneficial in large scale networks which currently contain hundreds of ACLs. By using the object-group ACL feature, the number of ACEs per ACL are significantly reduced. Object-group ACLs are also more readable, and easier to manage than conventional ACLs. Using object-group ACLs instead of conventional ACLs optimizes the storage needed in TCAM.

Bincode size enhancement

Starting with Cisco IOS XR Release 25.4.1, you can use P100-based ASICs that support an increased bincode size of 18 bits from 14 bits. This enhancement allows you to process network policies and configurations that require longer or more detailed prefix lists. This enhancement enables greater scalability and efficiency for managing network object-groups and ACLs on P100-based ASICs.

Starting with Cisco IOS XR Release 25.2.1, the bincode size for both source and destination prefixes has been increased from 24 bits to 26 bits. This enhancement supports network object-groups with longer prefix lists, improving scalability for applications requiring longer source and destination prefix lists.


Types of hybrid ACLs

You can create two types of object-group ACLs on Cisco IOS XR:

  • Network object-group ACLs: Consist of groups of host IP Addresses and network IP addresses.

  • Port object-group ACLs: Consist of groups of ports and supporting Layer 3 or Layer 4 protocols.


ACL compression

ACL compression is an object-group ACL mechanism that

  • accommodates a large number of ACEs by compressing selected ACE fields,

  • compresses the source IP prefix and destination IP prefix fields of an ACE, and

  • provides four compression levels for the access-group configuration on an ingress interface.

From Release 25.1.1 onwards, you can apply compression levels for object-group ACLs, also known as hybrid ACLs, at the egress traffic on P100-based ASICs.

Compression levels

There are four compression levels in the access-group configuration for an ACL on an ingress interface:

  • Compress level 0: No compression is done on the ACE fields.

    In this mode, the object-group ACL behaves like a traditional ACL.

  • Compress level 1: Only the source IP field in an ACE is compressed.

    A User-Defined Key (UDK) for compression level 1 can be configured using the following commands:

    hw-module profile tcam format access-list ipv4 src-object-group src-port dst-port proto tcp-flags frag-bit dst-addr 
    hw-module profile tcam format access-list ipv6 src-object-group src-port dst-port next-hdr frag-bit tcp-flags dst-addr 
  • Compress level 2: Two fields (source IP and destination IP) in an ACE are compressed.

    In this mode, for ingress traffic, central EM (Exact Match) is used for prefix lookup, and internal TCAM is used for ACE lookup.

    For egress traffic, central TCAM is used for both prefix lookup and ACE lookup.

  • Compress level 4: Only the destination IP field in an ACE is compressed.

    A UDK for compression level 4 can be configured using the following commands:

    hw-module profile tcam format access-list ipv4 src-addr src-port dst-port proto tcp-flags frag-bit dst-object-group 
    hw-module profile tcam format access-list ipv6 src-addr src-port dst-port next-hdr frag-bit tcp-flags dst-object-group 

Restrictions for hybrid ACLs

Hybrid ACL restrictions

These restrictions apply when you configure hybrid ACLs:

  • hybrid ACLs can only be configured to an interface. They cannot be used or referenced by applications like SSH, SNMP, NTP.

  • To delete an hybrid, you must first delete it from all ACLs.

  • You cannot configure hybrid ACLs along with QoS policies.

  • hybrid ACLs are not supported in any policy based configuration.

  • Any inline ACE update to an object group ACL clears complete stats of the ACL.

Egress hybrid ACL restrictions

These restrictions apply when you configure egress hybrid ACLs:

  • The 8011-4G24Y4H-I router does not support egress hybrid ACLs.

  • Egress hybrid ACLs do not support the 24-bit compression feature for object-group ACLs; this feature applies only to ingress ACLs.

  • The slice-aware prefix programming for egress object-group ACLs optimization is specific to Egress Object-Group ACLs. Ingress OG-ACLs continue to use LPM (Longest Prefix Match) or CEM (Content Exact Match) programming.