Authored by:
David Lorame, Technical Director & Senior Network Architect
Expertise:
Last Updated:
If you read the official Cisco datasheet for the Catalyst 1200 Series, you will see the standard promise: "wire-speed, non-blocking performance." But as any seasoned network architect knows, datasheet numbers are generated in perfectly sterile environments with zero security rules and flat Layer 2 topologies.
What happens when you deploy this budget-friendly edge switch in a real enterprise environment? Specifically, what happens when you push it to its absolute limits by maxing out the Access Control Lists (ACLs) while simultaneously forcing it to handle heavy Inter-VLAN routing?
To add an independent data point, the Network-Switch engineering team ran traffic against a Catalyst 1200-24P-4G with a Spirent traffic generator, 512 configured ACEs, eight routed VLANs, and static routing. The figures below are Network-Switch observations, not Cisco-rated performance values.
Evidence boundary: Exact firmware/build, test date, hardware revision, Spirent model and software, port map, trial duration, repeat count, offered/received frame tables, latency export, and raw logs are not attached to this public article. Therefore, the displayed 88.5% throughput, approximately 3-to-12-microsecond latency change, CPU history, and 99% ACL-logging observation should be treated as directional Network-Switch observations, not independently reproducible results. TCAM, ARP/MAC convergence, and packet-punt explanations are engineering interpretations unless a counter or controlled comparison is shown.
Commercial disclosure: Network-Switch sells network equipment and may recommend products mentioned in this article. Official specifications, our observations, engineering interpretations, and buying recommendations are separated so readers can evaluate each claim.
The Lab Setup: Pushing the TCAM to the Brink
The Catalyst 1200 is designed as a lightweight L2/L3-lite switch. Its internal TCAM (Ternary Content-Addressable Memory) resources are finite. We configured the switch with:
- Inter-VLAN Routing: 8 active VLANs with static routing enabled.
- Maximum ACLs: 512 ACEs (Access Control Entries) applied inbound across the VLAN interfaces, inspecting Layer 4 TCP/UDP ports.
- Traffic Profile: Bidirectional traffic mapping with RFC 2544 used as a methodology reference. Because the public evidence package does not include the complete trial duration, search procedure, repeat count, frame-loss table, and raw export, this article does not claim full RFC 2544 conformance.
The Real-World Results
1. Throughput Drop on Small Packets (64-byte)
In the recorded Network-Switch run, 1518-byte traffic reached the configured line-rate target. Cisco's data sheet separately rates the series as wire-speed and nonblocking. The public article does not include the raw 1518-byte offered/received frame table, so this sentence records our observation rather than an independently reproducible benchmark.
Network-Switch observation: with 512 configured ACL rules, the recorded 64-byte throughput was approximately 88.5% of the theoretical maximum, while the displayed latency moved from about 3 to 12 microseconds. These values are not Cisco specifications and the raw Spirent export is not attached. Increased lookup pressure is a plausible TCAM-related explanation, but the current evidence does not include TCAM utilization counters or a controlled comparison that proves the cause.
2. CPU Utilization Spikes and Stabilization
Cisco documents hardware resource and CPU monitoring for the platform. In this run, the displayed CPU history changed during traffic startup; the page does not include synchronized hardware-resource or trapped-packet counters, so the exact forwarding path and mechanism remain unverified.
During the first five seconds of the recorded traffic burst, the displayed CPU history rose and then stabilized. ARP and MAC convergence is a possible explanation, but the current public record does not include synchronized ARP/MAC counters that establish causation:
Cat1200# show processes cpu history
11111111112222222222333333333344444444445555555555
00000000000000000000000000000000000000000000000000
100
90
80
70 *
60 * *
50 * * * * * *
40 * * * * * * * * * * * * * * * * * * * * * * * * *
30 * * * * * * * * * * * * * * * * * * * * * * * * *
20 * * * * * * * * * * * * * * * * * * * * * * * * *
10 * * * * * * * * * * * * * * * * * * * * * * * * *
0....5....1....1....2....2....3....3....4....4....5....
0 5 0 5 0 5 0 5 0
Seconds
CPU utilization for five seconds: 71%; one minute: 42%; five minutes: 18%
Network-Switch observation: in the recorded high-rate run, enabling ACL logging coincided with CPU utilization reaching 99% and poor Web UI/SSH responsiveness. Cisco documentation supports that logged ACL matches can generate SYSLOG, but the current public evidence does not prove that every matched packet was punted or that hardware offload completely failed. Reproduce this only in an isolated test environment.
Architect's Takeaway
Is the Catalyst 1200 a bad switch? Absolutely not. It is an incredibly robust access switch for its price point. These observations support treating the Catalyst 1200 as an access/edge platform rather than assuming it will match a Catalyst 9300 under every routing and policy workload. Final selection still depends on the exact PID, firmware, feature scale, traffic mix, and acceptance test.
For a design with hundreds of L4 policy entries and heavy Inter-VLAN routing, validate the exact workload before purchase and consider moving policy enforcement to a firewall or distribution-layer platform. For adjacent access-layer decisions, review the Catalyst 1200 PoE guide and Catalyst 1200 SFP compatibility guide. Expected results should be written into a model-, firmware-, and traffic-specific acceptance plan rather than guaranteed by this article.
Frequently asked questions (FAQs)
How many ACL rules (ACEs) can the Catalyst 1200 actually hold?
Cisco's current data sheet lists support for up to 512 ACL rules for the series. Treat this as a documented scale limit, not proof of a universal post-limit forwarding behavior; verify the exact PID, firmware, resource status, configuration acceptance, and logs.
Why does turning on "ACL Logging" cause the Catalyst 1200 to freeze?
ACL logging can generate SYSLOG and add control-plane work. In the recorded Network-Switch run, logging coincided with 99% CPU and degraded management responsiveness, but the current public evidence does not prove a universal every-packet punt or complete offload failure.
Can the Catalyst 1200 handle OSPF or dynamic routing?
Cisco's current Catalyst 1200 data sheet documents static IPv4 routing and related scale values. Do not infer an OSPF/EIGRP entitlement from that positioning; verify the exact firmware's administration guide and feature list before selecting a platform for dynamic routing.
Does Inter-VLAN routing reduce PoE power capacity?
Enabling Inter-VLAN routing does not change the switch's published PoE budget, but the statement 'zero impact' is not established for every load, temperature, PSU, and redundancy condition. Verify the exact model's allocated/available PoE power and system health under the intended load.
Is the throughput drop on 64-byte packets noticeable to end-users?
The 88.5% figure came from one Network-Switch 64-byte test condition and cannot predict user experience by itself. Impact depends on packet-size distribution, offered load, loss, latency, jitter, application SLA, and traffic mix; test the intended workload before acceptance.
References & Official Documents
- Cisco Catalyst 1200 Series Switches Data Sheet (Official Specifications).
- Cisco Catalyst 1200 Administration Guide: Status and Statistics (CPU, hardware-resource, and counter inspection).
- IETF RFC 2544 (Benchmarking Methodology for Network Interconnect Devices).
https://network-switch.com/pages/david-lorame