> see both counters from "sh access-list" and "sh tcam interface.."
> increasing at nearly the same rate (see below).
> 
> I use 2 extended ACLs applied to an interface for filtering
> inbound/outbound traffic. There is plenty of TCAM space, I 
> don't use log
> statement, "no ip unreachables" is configured on each interface.....
> What I'm missing.

Below you have 
mls rate-limit unicast ip icmp unreachable acl-drop 1000 10
So 1000 pps will pass, try 
mls rate-limit unicast ip icmp unreachable acl-drop 0
To stop any packet dropped by acl getting to the cpu

 
> mls rate-limit unicast ip rpf-failure 0
> mls rate-limit unicast ip icmp redirect 0
> mls rate-limit unicast ip icmp unreachable no-route 1000 10
> mls rate-limit unicast ip icmp unreachable acl-drop 1000 10
> mls rate-limit unicast ip errors 1000 10
> mls rate-limit all ttl-failure 1000 10
> mls rate-limit all mtu-failure 1000 10
> 
> _______________________________________________
> cisco-nsp mailing list  [email protected]
> https://puck.nether.net/mailman/listinfo/cisco-nsp
> archive at http://puck.nether.net/pipermail/cisco-nsp/
> 

_______________________________________________
cisco-nsp mailing list  [email protected]
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/

Reply via email to