White Papers

Table Of Contents
Parameters
default Reset the number of FP blocks to the default value. By default, 0 FP blocks of
CAM are allocated for ACL VLAN services, such as iSCSI counters, Open Flow, and
ACL VLAN optimization.
NOTE: CAM optimization for ACL VLAN groups is not enabled by default. You
must allocate FP blocks of ACL VLAN CAM to enable ACL CAM optimization.
vlanopenflow
<0-2>
Allocate a number FP blocks of CAM for VLAN Open Flow operations.
vlaniscsi <0-2> Allocate a number FP blocks of CAM for VLAN iSCSI counters.
vlanaclopt <0-2> Allocate a number of FP blocks of CAM for CAM optimization of ACL VLAN
operation.
Default To reset the number FP blocks allocated for ACL VLAN processes, enter the default keyword with the
cam-acl-vlan command. By default, 0 FP blocks are allocated for ACL VLAN operations on the switch.
Command Modes ACL-VLAN-GROUP CONFIGURATION
Command
History
Version 9.5(0.1) Introduced on the Z9500.
Version 9.3(0.0) Introduced on the S4810 and Z9000.
Usage
Information
The VLAN ContentAware Processor (VCAP) application is a pre-ingress CAP that modifies the VLAN
settings before packets are forwarded. To support the ACL CAM optimization functionality, the CAM
carving feature is enhanced. A total of four VACP groups are present, of which two are for fixed groups
and the other two are for dynamic groups. Out of the total of two dynamic groups, you can allocate zero,
one, or two flow processor (FP) blocks to iSCSI counters, Open Flow and ACL VLAN optimization. You
can configure CAM FP blocks for only two of these ACL VLAN services at a time.
description (ACL VLAN Group)
Add a text description of an ACL VLAN group.
Syntax
description text
Parameters
description
Enter a text to identify the ACL VLAN group (80 characters maximum).
Default No default behavior or values
Command Modes ACL-VLAN-GROUP CONFIGURATION (conf-acl-vl-grp)
Command
History
Version 9.5.(0.0) Introduced on the Z9500.
Version 9.3.(0.0) Introduced on the S4810, S4820T, and Z9000.
Usage
Information
Enter a description for each ACL VLAN group that you create for effective administrative and logging
purposes.
ip access-group (ACL VLAN Group)
Apply an egress IP ACL to the ACL VLAN group.
Syntax
ip access-group access-list-name out implicit-permit
Parameters
access-list-name
Enter the name of the egress IP ACL to be applied to member interfaces of the
VLAN group (140 characters maximum).
out Enter the keyword out to apply the ACL to outgoing traffic.
implicit-permit
Enter the keyword implicit-permit to change the default action of the ACL
from implicit-deny to implicit-permit (that is, if the traffic does not match the
filters in the ACL, the traffic is permitted instead of dropped).
Access Control Lists (ACL) 201