Configuring IP ACLs
Verifying the IP ACL Configuration
To display IP ACL configuration information, perform one of the following tasks.
Command
show hardware access-list tcam region
show hardware access-list tcam template {all | nfe | nfe2 | l2-l3 | l3 |
template-name}
show ip access-lists
show ipv6 access-lists
show logging ip access-list cache [detail]
Cisco Nexus 9000 Series NX-OS Security Configuration Guide, Release 9.x
Verifying the IP ACL Configuration
Purpose
Displays the TCAM sizes that will
be applicable on the next reload of
the device.
Displays the configuration for all
TCAM templates or for a specific
template.
nfe—The default TCAM template
for Network Forwarding Engine
(NFE)-enabled Cisco Nexus 9300
and 9500 Series, 3164Q, and
31128PQ devices.
nfe2—The default TCAM template
for NFE2-enabled Cisco Nexus
9500, 3232C, and 3264Q devices.
l2-l3—The default TCAM template
for Layer 2 and Layer 3
configurations on Cisco Nexus
9200 Series switches.
l3—The default TCAM template
for Layer 3 configurations on Cisco
Nexus 9200 Series switches.
Displays the IPv4 ACL
configuration.
Displays the IPv6 ACL
configuration.
Displays information on the active
logged flows, such as source IP and
destination IP addresses, source
port and destination port
information, and source interfaces.
If you entered the logging ip
access-list detailed command, the
output also includes the following
information: the access control
entry (ACE) sequence number,
ACE action, ACL name, ACL
direction, ACL filter type, and ACL
applied interface.
267