<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How Do Routers Handle Access Lists in Routing and SD-WAN</title>
    <link>https://community.cisco.com/t5/routing-and-sd-wan/how-do-routers-handle-access-lists/m-p/4135486#M338283</link>
    <description>Generally, on the smaller routers, everything is done by the main CPU, without hardware support.  (Larger, or more powerful, routers [e.g. 7300 vs. 7200], have some additional hardware to accelerate some functions - some of the largest "routers" are/were really L3 switches, with more functions [e.g. 7600 vs. 6500].)&lt;BR /&gt;&lt;BR /&gt;On those routers, doing everything in software, something like ACLs, might be done in some way to "optimize" how they are processed.  Or, on some routers, starting with the 7200 series, they had an optional "compile" ACL function, which was supposed to greatly increase performance for long ACLs.  (Much of such optimization is likely considered proprietary.)</description>
    <pubDate>Thu, 13 Aug 2020 17:48:17 GMT</pubDate>
    <dc:creator>Joseph W. Doherty</dc:creator>
    <dc:date>2020-08-13T17:48:17Z</dc:date>
    <item>
      <title>How Do Routers Handle Access Lists</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/how-do-routers-handle-access-lists/m-p/4135408#M338275</link>
      <description>&lt;P&gt;Hi, all. Just a quick basic question. I'm aware of how L3 switches handle standard and extended access lists, where the entries are used to populate the TCAM and multiple ACEs can be processed simultaneously. I'm not sure how routers carry out their processing of ACLs, or if they're handled in hardware as seen with a switch. Specifically 1941 and 4330 models, if there's any variation. I'm hoping someone can inform me or provide some documentation for me to educate myself.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Aug 2020 16:07:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/how-do-routers-handle-access-lists/m-p/4135408#M338275</guid>
      <dc:creator>WGL_BK</dc:creator>
      <dc:date>2020-08-13T16:07:20Z</dc:date>
    </item>
    <item>
      <title>Re: How Do Routers Handle Access Lists</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/how-do-routers-handle-access-lists/m-p/4135481#M338282</link>
      <description>&lt;P&gt;Hope below information help you :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="http://etutorials.org/Networking/Router+firewall+security/Part+III+Nonstateful+Filtering+Technologies/Chapter+6.+Access+List+Introduction/Access+List+Overview/" target="_blank"&gt;http://etutorials.org/Networking/Router+firewall+security/Part+III+Nonstateful+Filtering+Technologies/Chapter+6.+Access+List+Introduction/Access+List+Overview/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Aug 2020 17:43:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/how-do-routers-handle-access-lists/m-p/4135481#M338282</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2020-08-13T17:43:15Z</dc:date>
    </item>
    <item>
      <title>Re: How Do Routers Handle Access Lists</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/how-do-routers-handle-access-lists/m-p/4135486#M338283</link>
      <description>Generally, on the smaller routers, everything is done by the main CPU, without hardware support.  (Larger, or more powerful, routers [e.g. 7300 vs. 7200], have some additional hardware to accelerate some functions - some of the largest "routers" are/were really L3 switches, with more functions [e.g. 7600 vs. 6500].)&lt;BR /&gt;&lt;BR /&gt;On those routers, doing everything in software, something like ACLs, might be done in some way to "optimize" how they are processed.  Or, on some routers, starting with the 7200 series, they had an optional "compile" ACL function, which was supposed to greatly increase performance for long ACLs.  (Much of such optimization is likely considered proprietary.)</description>
      <pubDate>Thu, 13 Aug 2020 17:48:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/how-do-routers-handle-access-lists/m-p/4135486#M338283</guid>
      <dc:creator>Joseph W. Doherty</dc:creator>
      <dc:date>2020-08-13T17:48:17Z</dc:date>
    </item>
    <item>
      <title>Re: How Do Routers Handle Access Lists</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/how-do-routers-handle-access-lists/m-p/4135494#M338285</link>
      <description>Ah, thank your for the explanation, Joseph. I was hoping to find exactly how the 4331 router did it, but I've had no luck thus far. Is it safe to assume that if there's no way to configure the SDM on a device, then that that device does not use hardware based TCAM?</description>
      <pubDate>Thu, 13 Aug 2020 17:59:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/how-do-routers-handle-access-lists/m-p/4135494#M338285</guid>
      <dc:creator>WGL_BK</dc:creator>
      <dc:date>2020-08-13T17:59:43Z</dc:date>
    </item>
    <item>
      <title>Re: How Do Routers Handle Access Lists</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/how-do-routers-handle-access-lists/m-p/4135496#M338286</link>
      <description>Thank you, Balaji. I'll get to reading through this.</description>
      <pubDate>Thu, 13 Aug 2020 18:00:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/how-do-routers-handle-access-lists/m-p/4135496#M338286</guid>
      <dc:creator>WGL_BK</dc:creator>
      <dc:date>2020-08-13T18:00:24Z</dc:date>
    </item>
    <item>
      <title>Re: How Do Routers Handle Access Lists</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/how-do-routers-handle-access-lists/m-p/4135532#M338291</link>
      <description>&lt;P&gt;A device not supporting a SDM template doesn't insure there's not any TCAM. What the SDM does, is tell the device how you would like the TCAM resources allocated (among vendor allowed choices).&lt;BR /&gt;&lt;BR /&gt;Again, how Cisco, for something like a 4331 actually/exactly does ACL processing, is likely considered proprietary, which if so, would very much explain why you cannot find any documentation on that.&lt;BR /&gt;&lt;BR /&gt;The CPU would likely do some boolean operation(s) between the packet vs. the ACL. Again, if Cisco is clever, they might "optimize" how the comparison is actually done. For example, given:&lt;BR /&gt;&lt;BR /&gt;access-list 10 deny host 192.168.1.0&lt;BR /&gt;access-list 10 deny host 192.168.1.1&lt;BR /&gt;access-list 10 deny host 192.168.1.2&lt;BR /&gt;access-list 10 deny host 192.168.1.3&lt;BR /&gt;access-list 10 deny host 192.168.1.4&lt;BR /&gt;access-list 10 deny host 192.168.1.5&lt;BR /&gt;access-list 10 deny host 192.168.1.6&lt;BR /&gt;access-list 10 deny host 192.168.1.7&lt;BR /&gt;&lt;BR /&gt;There's eight ACEs, in the above ACL, but they can be done as one ACE, as:&lt;BR /&gt;&lt;BR /&gt;access-list 10 deny 192.168.1.0 0.0.0.7&lt;BR /&gt;&lt;BR /&gt;Doing one operation rather than eight, should be eight times faster. One question would be, is the IOS "smart enough" to automatically do just the one operation rather than the eight?&lt;BR /&gt;&lt;BR /&gt;Or given:&lt;BR /&gt;&lt;BR /&gt;access-list 10 deny host 192.168.1.2&lt;BR /&gt;access-list 10 deny host 192.168.1.3&lt;BR /&gt;access-list 10 deny host 192.168.1.4&lt;BR /&gt;access-list 10 deny host 192.168.1.5&lt;BR /&gt;access-list 10 deny host 192.168.1.6&lt;BR /&gt;access-list 10 deny host 192.168.1.7&lt;BR /&gt;&lt;BR /&gt;This could be done as:&lt;BR /&gt;&lt;BR /&gt;access-list 10 permit 192.168.1.0 0.0.0.1&lt;BR /&gt;access-list 10 deny 192.168.1.0 0.0.0.7&lt;BR /&gt;&lt;BR /&gt;Two operations are better than six. Again, does the IOS figure this out?&lt;BR /&gt;&lt;BR /&gt;Or course, you can (perhaps) optimize ACL processing, by providing the ACL with optimal ACEs.&lt;BR /&gt;&lt;BR /&gt;That aside, as noted in my other post, what you would do would be compare the packet's source IP, with the information in the ACE.&lt;BR /&gt;&lt;BR /&gt;For example, if packet had an source IP of 192.168.1.3, depending on the ACE you would logically compare that source IP with both the address and mask values in the ACE, determining if there's a match. A source IP of 192.168.1.3 would match host 192.168.1.3 or 192.168.1.0 0.0.0.7.&lt;BR /&gt;&lt;BR /&gt;Understand, also, what boolean operations some hardware provides (to the CPU) can impact the actual "how" for some operations.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Aug 2020 18:47:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/how-do-routers-handle-access-lists/m-p/4135532#M338291</guid>
      <dc:creator>Joseph W. Doherty</dc:creator>
      <dc:date>2020-08-13T18:47:19Z</dc:date>
    </item>
    <item>
      <title>Re: How Do Routers Handle Access Lists</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/how-do-routers-handle-access-lists/m-p/4135542#M338294</link>
      <description>Thank you again, Joseph. You've been most helpful.</description>
      <pubDate>Thu, 13 Aug 2020 19:02:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/how-do-routers-handle-access-lists/m-p/4135542#M338294</guid>
      <dc:creator>WGL_BK</dc:creator>
      <dc:date>2020-08-13T19:02:12Z</dc:date>
    </item>
    <item>
      <title>Re: How Do Routers Handle Access Lists</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/how-do-routers-handle-access-lists/m-p/4135563#M338298</link>
      <description>&lt;P&gt;Oh, my examples were simple, but the two boolean operators used, for actual matching packet's attributes (in my examples, just source IP address) against ACE are (I believe) the boolean And and Xor operators.&lt;BR /&gt;&lt;BR /&gt;To see how the IOS, or you, could combine multiple ACEs into one, you might read: &lt;A href="https://www.imedita.com/blog/wildcard-masks" target="_blank" rel="noopener"&gt;https://www.imedita.com/blog/wildcard-masks&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Aug 2020 19:47:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/how-do-routers-handle-access-lists/m-p/4135563#M338298</guid>
      <dc:creator>Joseph W. Doherty</dc:creator>
      <dc:date>2020-08-13T19:47:19Z</dc:date>
    </item>
  </channel>
</rss>

