<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic object and object group limits - context firewall in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/object-and-object-group-limits-context-firewall/m-p/3096484#M133174</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I have a cisco 5585, software version 9.5(2)2 running in context mode.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Could someone please tell me the maximum number of objects I can have in a single context firewall, the maximum number of objects I can have in an object group in a single context firewall and how many object groups I can have in each acl?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Also, is it possible to block IP address ranges by geographical region versus ip host or&amp;nbsp; cidr block addresses?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thank you.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 09:50:31 GMT</pubDate>
    <dc:creator>lkadlik</dc:creator>
    <dc:date>2019-03-12T09:50:31Z</dc:date>
    <item>
      <title>object and object group limits - context firewall</title>
      <link>https://community.cisco.com/t5/network-security/object-and-object-group-limits-context-firewall/m-p/3096484#M133174</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I have a cisco 5585, software version 9.5(2)2 running in context mode.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Could someone please tell me the maximum number of objects I can have in a single context firewall, the maximum number of objects I can have in an object group in a single context firewall and how many object groups I can have in each acl?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Also, is it possible to block IP address ranges by geographical region versus ip host or&amp;nbsp; cidr block addresses?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thank you.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 09:50:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/object-and-object-group-limits-context-firewall/m-p/3096484#M133174</guid>
      <dc:creator>lkadlik</dc:creator>
      <dc:date>2019-03-12T09:50:31Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-security/object-and-object-group-limits-context-firewall/m-p/3096485#M133176</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;There is no limit for configuring objects in a single context ASA.&lt;/P&gt;
&lt;P&gt;However, there is a limitation on the number of access-control elements on a specific&amp;nbsp;hardware.&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;There is no hard-coded limit on the number of elements (access control entries) in an ACL, which is bound only by memory. Each ACE uses a minimum of 212 bytes of RAM. However maximum performance may decrease (typically by 10 to 15 percent as you reach or exceed the recommended maximum number of ACEs.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Please check the link for ASA 5585 ( Section:&amp;nbsp;&lt;/SPAN&gt;What is the maximum ACL limit on ASA)?&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;https://www.cisco.com/c/en/us/products/collateral/security/adaptive-security-appliance-asa-software/qa_c67-731962.html&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Also, is it possible to block IP address ranges by geographical region versus ip host &lt;G class="gr_ gr_266 gr-alert gr_gramm gr_inline_cards gr_run_anim Style multiReplace" id="266" data-gr-id="266"&gt;or&amp;nbsp; cidr&lt;/G&gt; block addresses?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;On ASA you can only use CIDR block to block IP address, only if use Sourcefire module on ASA you would be able to block on geographical region.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Aditya&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Please rate helpful and mark correct answers&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Aug 2017 03:31:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/object-and-object-group-limits-context-firewall/m-p/3096485#M133176</guid>
      <dc:creator>Aditya Ganjoo</dc:creator>
      <dc:date>2017-08-18T03:31:47Z</dc:date>
    </item>
  </channel>
</rss>

