
Have a Cisco Catalyst 6000 or a 7600 and don't see any matches when you issue a "show access-list"? This is due to these platforms performing this function in hardware and not in the MSFC:
"The show access-list command displays statistics only for traffic that matches ACLs processed in software on the MSFC. The show access-list command does not display statistics for traffic that matches an ACL supported in hardware on the PFC. (CSCdt14386)"
So when you don't see matches here:
core01#sh access-list 2020
Extended IP access list 2020
10 permit ip host 10.100.56.21 any
20 permit ip host 10.100.56.23 any (1 match)
30 permit ip host 10.100.56.24 any
40 permit ip host 10.100.56.25 any (1 match)
50 permit ip host 10.100.56.26 any
60 permit ip host 10.100.56.27 any
70 permit ip host 10.100.56.28 any (2 matches)
Do this instead:
core01#sh tcam interface Vlan1000 acl in ip
* Global Defaults shared
Entries from Bank 0
Entries from Bank 1
permit ip any 224.0.0.0 15.255.255.255 (17642 matches)
policy-route ip host 10.100.56.21 any (616218 matches)
policy-route ip host 10.100.56.23 any (6518782 matches)
policy-route ip host 10.100.56.24 any (6694712 matches)
policy-route ip host 10.100.56.25 any (6820337 matches)
policy-route ip host 10.100.56.26 any (7223011 matches)
policy-route ip host 10.100.56.27 any (7133610 matches)
policy-route ip host 10.100.56.28 any (6811648 matches)
 






