How many filters can you create?

How many filters can you create?

The total number of filters that can be created is not an exact number, but depends on which fields the various filters are matching on. So, to understand how to work out whether the set of filters you are creating might run out of space, it is necessary to understand the way in which the filters operate in the switch hardware.

There are two items within the switch hardware which set limits on the number of filters that can be created: the filter rules table and the profile (mask).

Filters share the same filter rules table and mask whether they are made by applying ACLs directly to ports or are made through QoS class-maps.

1. The filter rules table

One item that sets a limit on the number of filters is the table that contains the list of filter rules. This has a strict limit of 1024 entries. An entry gets made when:

zYou apply an ACL to a port (with the ip access-groupor mac access-groupcommand)

zYou apply a QoS class-map to a port by applying its policy-map to a port (with the service- policy input command). For each class-map, its ACL and any match commands are ANDed together to make a single filter entry.

Therefore, every ACL or class-map uses up one table entry for every port that it is applied to. Interface ACL rules come before QoS class-map rules. Conceptually, the table looks like:

port1.0.1

Interface ACL rule

 

Interface ACL rule

 

...

 

QoS class-map rule

 

QoS class-map rule

 

...

 

 

port1.0.2

Interface ACL rule

 

Interface ACL rule

 

...

 

QoS class-map rule

 

QoS class-map rule

 

...

 

 

...

...

 

 

If you specify a TCP or UDP port range, this may use multiple filter entries. The switch converts the range to a series of single TCP/UDP port numbers plus masks. It uses as few entries as possible to cover the range.

Also, the protocols that use filters (CPU protection and EPSR—see page 21) create one entry per port.

Page 18 AlliedWare Plus™ OS How To Note

Page 18
Image 18
Allied Telesis x908, X900-12XT/S manual How many filters can you create?, Filter rules table

X900-12XT/S, x908 specifications

The Allied Telesis x908 and the SwitchBlade x900 series of network switches are cutting-edge solutions designed to address the demands of modern networking environments. These switches are known for their high performance, reliability, and robust feature sets, making them ideal for enterprise and service provider networks.

The Allied Telesis x908 series consists of modular and chassis-based systems that can accommodate a variety of network configurations. One of the main features of the x908 series is its ability to offer high scalability with support for a large number of ports. This makes it suitable for data centers and large enterprise networks where space and bandwidth optimization are critical.

In addition to scalability, the x908 series supports advanced Layer 2 and Layer 3 switching capabilities. This allows for efficient traffic management and routing, ensuring that data is delivered swiftly and reliably. The x908 also incorporates intelligent features such as Quality of Service (QoS), which prioritizes critical network traffic, ensuring that time-sensitive data—like voice and video—maintains its quality during transmission.

The SwitchBlade x900 series takes this functionality further with its innovative modular architecture. This allows organizations to configure their networks to meet specific needs by choosing from a variety of interface cards and service modules. The SwitchBlade x900 also supports advanced security features such as Access Control Lists (ACLs) and VLAN segmentation, which provide enhanced protection against unauthorized access and network threats.

Another hallmark of the x908 and SwitchBlade series is their support for high-speed Ethernet technologies, including 10G and 40G Ethernet. This enables organizations to keep pace with the increasing bandwidth demands of applications and services, particularly in cloud computing and data-intensive workloads.

Both the x908 and the SwitchBlade x900 series are designed with energy efficiency in mind, featuring power-saving technologies that reduce overall operational costs. Coupled with Allied Telesis' management tools, which provide detailed analytics and monitoring, network administrators can optimize performance and energy consumption simultaneously.

In summary, the Allied Telesis x908 and SwitchBlade x900 series offer a comprehensive suite of features, high performance, scalability, and advanced networking technologies. They represent a strategic investment for organizations looking to build resilient, efficient, and future-proof network infrastructures.