This chapter describes diagnostic and statistics features for ACLs on the Cisco 8000 Series Router, including user-defined TCAM keys, ACL counters and statistics, fragment control, packet length filtering, TTL matching, logging, and per-interface statistics.
This chapter contains the following sections:
User-defined TCAM keys for IPv4 and IPv6
This topic describes User-Defined TCAM Keys (UDKs) that provide flexibility to define a custom TCAM key for ingress IPv4 and IPv6 ACLs.
Access control list counters
This topic describes how access control list (ACL) counters are maintained in hardware and software on the Cisco 8000 Series Router.
ACL statistics counter
This topic describes how the ACL statistics counter feature on the Cisco 8000 Series Router tracks the count of packets that a router permits or denies based on the ACL rules configured on an interface.
ACLs with fragment control
This topic describes how the IP Extended Access Lists with Fragment Control feature provides granular control over non-initial IP fragments when you apply an IP extended access list.
ACL filtering by IP packet length
This topic describes the packet-length filtering feature in access control lists (ACLs) on the Cisco 8000 Series Router.
TTL matching
This topic describes how IPv4 access control lists (ACLs) match on the Time-to-Live (TTL) value in the IPv4 header.
IP access list logging messages
This topic describes the logging messages that Cisco IOS XR Software generates when packets are permitted or denied by a standard IP access list on the Cisco 8000 Series Router.
Interface logging on ACLs
This topic describes how interface logging on IPv4 and IPv6 access control lists (ACLs) generates log messages that identify the interface through which traffic enters or exits the router.
Per-interface statistics
This topic describes per-interface ACL entry (ACE) drop counters, which you enable by using the interface-statistics keyword when you bind an ACL to an interface.