<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Does the order of the ACL affect the CPU and other resources on the firepower FTD in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/does-the-order-of-the-acl-affect-the-cpu-and-other-resources-on/m-p/4293883#M1078590</link>
    <description>&lt;P&gt;I am curious, for all the Allow rules, does the order of the access control policy affect the platform in a large way?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What I mean is if there are a few hundred rules, is it important to put the most active flows at the top of the list and the rules that seldom get hit at the bottom?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can see time sensitive flows like voice traffic being important to be at the top of the list.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Overall, does it make a big impact to manage the order of the access policy or is the difference negligible?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 18 Feb 2021 19:12:53 GMT</pubDate>
    <dc:creator>Alex-Pr</dc:creator>
    <dc:date>2021-02-18T19:12:53Z</dc:date>
    <item>
      <title>Does the order of the ACL affect the CPU and other resources on the firepower FTD</title>
      <link>https://community.cisco.com/t5/network-security/does-the-order-of-the-acl-affect-the-cpu-and-other-resources-on/m-p/4293883#M1078590</link>
      <description>&lt;P&gt;I am curious, for all the Allow rules, does the order of the access control policy affect the platform in a large way?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What I mean is if there are a few hundred rules, is it important to put the most active flows at the top of the list and the rules that seldom get hit at the bottom?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can see time sensitive flows like voice traffic being important to be at the top of the list.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Overall, does it make a big impact to manage the order of the access policy or is the difference negligible?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Feb 2021 19:12:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/does-the-order-of-the-acl-affect-the-cpu-and-other-resources-on/m-p/4293883#M1078590</guid>
      <dc:creator>Alex-Pr</dc:creator>
      <dc:date>2021-02-18T19:12:53Z</dc:date>
    </item>
    <item>
      <title>Re: Does the order of the ACL affect the CPU and other resources on the firepower FTD</title>
      <link>https://community.cisco.com/t5/network-security/does-the-order-of-the-acl-affect-the-cpu-and-other-resources-on/m-p/4293908#M1078591</link>
      <description>&lt;P&gt;The CPU search match according to order of enter ACL, and hence it good for voice.&lt;/P&gt;&lt;P&gt;very good point.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Feb 2021 19:36:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/does-the-order-of-the-acl-affect-the-cpu-and-other-resources-on/m-p/4293908#M1078591</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2021-02-18T19:36:44Z</dc:date>
    </item>
    <item>
      <title>Re: Does the order of the ACL affect the CPU and other resources on the firepower FTD</title>
      <link>https://community.cisco.com/t5/network-security/does-the-order-of-the-acl-affect-the-cpu-and-other-resources-on/m-p/4293935#M1078592</link>
      <description>&lt;P&gt;IMO this depends on the type of hardware you are running.&amp;nbsp; AFAIK the 4110s can support up to 1.5 million ACEs (access control entries), and each platform has different support numbers.&amp;nbsp; I would recommend looking at your specific platform data sheet for a more accurate understanding of the limitations.&amp;nbsp; For FTD traffic handling have you considered prefilter policies to fastpath certain traffic? Pre-filtering is the first thing that gets checked in relation to the access control phase.&amp;nbsp; Fastpath essentially allows you to bypass further evaluation from within the snort engine.&amp;nbsp; If you want to see more about traffic handling see here:&amp;nbsp;&lt;A href="https://www.learnitwithcifelli.com/post/understanding-firepower-packet-processing" target="_blank"&gt;Understanding Firepower Packet Processing (learnitwithcifelli.com)&lt;/A&gt;.&amp;nbsp; HTH!&lt;/P&gt;</description>
      <pubDate>Thu, 18 Feb 2021 20:20:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/does-the-order-of-the-acl-affect-the-cpu-and-other-resources-on/m-p/4293935#M1078592</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2021-02-18T20:20:17Z</dc:date>
    </item>
  </channel>
</rss>

