IP Addresses and Services Configuration Guide for Cisco 8000 Series Routers, IOS XR Releases

PDF

IP Addresses and Services Configuration Guide for Cisco 8000 Series Routers, IOS XR Releases

User-defined TCAM keys for IPv4 and IPv6

Want to summarize with AI?

Log in

This topic describes User-Defined TCAM Keys (UDKs) that provide flexibility to define a custom TCAM key for ingress IPv4 and IPv6 ACLs.


The TCAM (internal and external) Key Definition is a configuration component that

  • specifies qualifier and action fields for packet lookups

  • optimizes the utilization of constrained hardware TCAM space, and

  • determines the available key width for ACL operations.

The key definitions are specific to a given ACL type, which can depend on the following attributes of the access list:

  • Direction of attachment only for ingress

  • Protocol type (IPv4/IPv6)

Because the default key definitions are constrained (do not include all qualifier/action fields), User-Defined Key (UDK) definitions are supported for the following types:

  • Traditional Ingress IPv4 ACL (uncompressed)

  • Traditional Ingress IPv6 ACL (uncompressed)

The User-Defined TCAM Key (UDK) functionality provides the flexibility to define your own TCAM key for ingress, traditional, or IPv4 and IPv6 ACL only. To include the well-known fields in the default TCAM key, see IPv4 and IPv6 key formats.

A User-Defined TCAM Key (UDK) can be defined globally or locally per line card. If both global and local UDK is available for a line card, then global UDK is ignored for the line card.

Configure UDK

A UDK can be configured using the following command:

hw-module profile tcam format access-list [ipv4 | ipv6] field1 field2[location rack/slot/cpu0] 

To define UDK globally, you can ignore the location option.

hw-module profile tcam format access-list [ipv4 | ipv6] field1 field2 
Note

Use global UDK for Cisco 8000 Series Routers Fixed platform.


IPv4 and IPv6 key formats

Qualifier fields

The following table shows the qualifier fields that are supported in the IPv4 and IPv6 key formats.

Note

You cannot configure destination address and destination object group together for an ACL. Similarly, you cannot configure source address and source object group together for an ACL.

Table 1. Qualifier Fields Supported in IPv4 and IPv6 Key Formats

Parameter

Default TCAM Key

IPv4

IPv6

Destination Address

Supported

Supported

Destination Object Group

Supported

Supported

Destination Port

Supported

Supported

Fragment bit

Supported

Supported

Fragment offset

Supported

Not Supported

Fragment type

Supported

Not Supported

ICMP type and code

Supported

Supported

IGMP type and code

Supported

Supported

Packet Length

Supported

Supported

Protocol/Next Header

Supported

Supported

Precedence/DSCP

Supported

Supported

Source Object Group

Supported

Supported

Source Address

Supported

Supported

Source Port

Supported

Supported

TCP Flags

Supported

Supported for Ingress only

Time to live (TTL) Match

Supported

Not supported

UDF 1-8

Not supported

Not supported

Note

IGMP header match for IPv4 in v2 and v3 reports is not supported.

Action fields

The following table shows the action fields supported in the IPv4 and IPv6 key formats.

Table 2. Action Fields Supported in IPv4 and IPv6 Key Formats

Parameter

Default Action Field

IPv4

IPv6

Permit

Supported

Supported

Deny

Supported

Supported

Next Hop

Supported

Supported

Log

Supported for Ingress only

Supported for Ingress only

Capture

Supports only ingress Encapsulated Remote SPAN (ERSPAN)

Supports only ingress Encapsulated Remote Switch port Analyzer (ERSPAN)

Stats Counter

Deny stats is always enabled (permit stats is enabled by the hw-module profile stats acl-permit command)

Deny stats is always enabled (permit stats is enabled by the hw-module profile stats acl-permit command)