This topic describes User-Defined TCAM Keys (UDKs) that provide flexibility to define a custom TCAM key for ingress IPv4 and IPv6 ACLs.
The TCAM (internal and external) Key Definition is a configuration component that
-
specifies qualifier and action fields for packet lookups
-
optimizes the utilization of constrained hardware TCAM space, and
-
determines the available key width for ACL operations.
The key definitions are specific to a given ACL type, which can depend on the following attributes of the access list:
-
Direction of attachment only for ingress
-
Protocol type (IPv4/IPv6)
Because the default key definitions are constrained (do not include all qualifier/action fields), User-Defined Key (UDK) definitions are supported for the following types:
-
Traditional Ingress IPv4 ACL (uncompressed)
-
Traditional Ingress IPv6 ACL (uncompressed)
The User-Defined TCAM Key (UDK) functionality provides the flexibility to define your own TCAM key for ingress, traditional, or IPv4 and IPv6 ACL only. To include the well-known fields in the default TCAM key, see IPv4 and IPv6 key formats.
A User-Defined TCAM Key (UDK) can be defined globally or locally per line card. If both global and local UDK is available for a line card, then global UDK is ignored for the line card.
Configure UDK
A UDK can be configured using the following command:
hw-module profile tcam format access-list [ipv4 | ipv6] field1 field2[location rack/slot/cpu0]
To define UDK globally, you can ignore the location option.
hw-module profile tcam format access-list [ipv4 | ipv6] field1 field2
Use global UDK for Cisco 8000 Series Routers Fixed platform.