An S series switch applies a traffic policy in which the ACL rule is configured as permit, but some permitted packets are counted as CPCAR dropped packets. Why

When S series fixed switches match received packets against rules, the priority of a traffic policy is higher than the priority of CPCAR. If both the CPCAR rate limit action and the permit action in a traffic policy take effect, a switch permits the matched packets and does not perform rate limitation on the packets.
A switch matches packets against both traffic policy rules and CPCAR and then takes the action of the highest priority. Therefore, permitted packets may be counted as CPCAR dropped packets during the rule matching phase.

