Loading...
Loading...
In a large scale ACL config using object-group, any ACE added after the OBG are not added to the hardware table, thereby causing the rule to be missing and the enforcement ignored. The described behavior in this bug can be seen if the supported scale number of ACEs in an ACL is exceeded. As a result, stuck objects and fp download error messages may be generated and not recover without reload. Also, the PI command will not be able to correctly display the total number of ACEs configured once the box enters the broken state.
This is seen when object-group is used in combination with regular ACEs. And the root cause is that maximum ACEs in expanded OGACL exceeds the supported maximum, and the platform resources such as memory and TCAM cannot handle it.
Delete the ACL, reconfigure it by moving the singular ACEs above the object-group before re-applying on the interface. This can make the new singular ACE work. Or scale can be reduced by removing some OG ACEs to fit the maximum 81920 limit for total expanded ACEs. For OG ACE, each ACE will be expanded to service OG entries * source OG network entries * destination OG network entries.
The issue is not seen when the maximum PI limit
Click on a version to see all relevant bugs
Cisco Integration
Learn more about where this data comes from
BugZero Plan
Streamline upgrades with automated vendor bug scrubs
BugZero Prevent
Wish you caught this bug sooner? Get proactive today.