Welcome, Guest: Register On Nairaland / LOGIN! / Trending / Recent / New
Stats: 3,195,015 members, 7,956,763 topics. Date: Monday, 23 September 2024 at 06:19 PM

Adding Rule Failed Due To Insufficient Resource - Science/Technology - Nairaland

Nairaland Forum / Science/Technology / Adding Rule Failed Due To Insufficient Resource (399 Views)

Facebook Criticised By Mps For 'insufficient Evidence' Over Data Handling / Why Is Nairaland Not Adding New Features And Changing It’s Interface? / Must Read!!! Bill Gates Regrets Adding This Very Popular Command (2) (3) (4)

(1) (Reply)

Adding Rule Failed Due To Insufficient Resource by jorna: 8:00am On Feb 27, 2017
Issue Description
New ACL rules cannot be added because of the ACL resource insufficient .
Alarm Information
Error: Adding rule failed. Insufficient resource in policy vlan 250 classifier vlan 250 behavior vlanPermit acl 3001, rule Bleep, on slot x vlan 250.
Handling Process
1. Initial configuration is shown below, different VLANs apply same traffic-policy
#
acl number 3001
description "Standard allow ACL"
rule 1 permit ospf source 172.x.250.0 0.0.0.255
rule 2 permit ospf source 172.x.251.0 0.0.0.255
rule 3 permit ip source 172.x.250.0 0.0.0.255
rule 4 permit ip source 172.x.251.0 0.0.0.255

#
traffic classifier pstv-acl operator or precedence 5
if-match acl 3001
#
traffic policy pstv-policy
classifier pstv-acl behavior pstv-behavior
#
vlan 250
traffic-policy pstv-policy inbound
vlan 251
traffic-policy pstv-policy inbound
#

2. Replace current traffic-policy with global policy, occupation of ACL resource reduces 50%
#
acl number 3001
description "Standard allow ACL"
rule 1 permit ospf source 172.x.250.0 0.0.0.255
rule 2 permit ospf source 172.x.251.0 0.0.0.255
rule 3 permit ip source 172.x.250.0 0.0.0.255
rule 4 permit ip source 172.x.251.0 0.0.0.255

#
traffic classifier pstv-acl operator and
if-match vlan-id 250 to 251
if-match acl 3001
#
traffic policy pstv-policy
classifier pstv-acl behavior pstv-behavior
#
traffic-policy pstv-policy global inbound
#
Root Cause
Traffic-policy including hundreds of ACL rules are applied in different VLANs. ACL resource will be depleted exponentially.
Suggestions
when differnet VLANs or interfaces apply same traffic policy, global policy can optimize ACL resource exponentially.

For more techinical information contact:
Telephone:852-30623083
Email:Sales@Thunder-link.com
Supports@Thunder-link.com
Webstite:http://www.thunder-link.com

(1) (Reply)

Google Allo: Smart Messaging App, Google Assistant, Reply Suggestions And More / See Funny-easy Way To Clear Cache In Google Chrome Quickly / Top Online Information Technology Learning Platforms/websites(www.techdashed.tk)

(Go Up)

Sections: politics (1) business autos (1) jobs (1) career education (1) romance computers phones travel sports fashion health
religion celebs tv-movies music-radio literature webmasters programming techmarket

Links: (1) (2) (3) (4) (5) (6) (7) (8) (9) (10)

Nairaland - Copyright © 2005 - 2024 Oluwaseun Osewa. All rights reserved. See How To Advertise. 7
Disclaimer: Every Nairaland member is solely responsible for anything that he/she posts or uploads on Nairaland.