<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic I was able to find more in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/maximum-rules-limit-on-5500-x-platforms/m-p/2969529#M144552</link>
    <description>&lt;P&gt;I was able to find more information on ACL recommended maximums in a cisco live session titled "Maximizing Firewall Performance". (2015)&lt;/P&gt;
&lt;P&gt;&lt;IMG width="684" height="91" alt="" src="https://community.cisco.com/legacyfs/online/attachments/discussion/acl-max.png" /&gt;&lt;/P&gt;
&lt;P&gt;Based on your platform you should be able to handle 200.000 ACEs. To verify your current number of ACE please execute the following command and post the output:&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;ASA# show access-list | include elements&lt;/PRE&gt;
&lt;P&gt;Depending on your output (count &amp;lt; 200k) please execute the following commands and&amp;nbsp;post the output&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;ASA# show version&lt;BR /&gt;ASA# show memory&lt;BR /&gt;ASA# show memory detail&lt;BR /&gt;ASA# show memory app-cache&lt;BR /&gt;ASA# show resource usage&lt;BR /&gt;ASA# show resource usage detail&lt;BR /&gt;ASA# show traffic&lt;BR /&gt;ASA# show blocks&lt;BR /&gt;ASA# show cpu core&lt;BR /&gt;ASA# show cpu detail&lt;/PRE&gt;</description>
    <pubDate>Wed, 30 Nov 2016 18:36:20 GMT</pubDate>
    <dc:creator>Oliver Kaiser</dc:creator>
    <dc:date>2016-11-30T18:36:20Z</dc:date>
    <item>
      <title>Maximum rules limit on 5500-X platforms</title>
      <link>https://community.cisco.com/t5/network-security/maximum-rules-limit-on-5500-x-platforms/m-p/2969526#M144547</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are in the process of migration from checkpoint to ASA with firepower services wherein the customer has more than one lakh rules that needs to be migrated to Cisco platform. Is there any documentation for referring the maximum rules count supported on our platform?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks &amp;amp; Regards,&lt;/P&gt;
&lt;P&gt;Yogesh Madhekar&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 08:36:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/maximum-rules-limit-on-5500-x-platforms/m-p/2969526#M144547</guid>
      <dc:creator>ymadheka</dc:creator>
      <dc:date>2019-03-12T08:36:00Z</dc:date>
    </item>
    <item>
      <title>The maximum number of rules</title>
      <link>https://community.cisco.com/t5/network-security/maximum-rules-limit-on-5500-x-platforms/m-p/2969527#M144549</link>
      <description>&lt;P&gt;The maximum number of rules depends on the platforms memory capacity. A single access-control-entry occupies about&amp;nbsp;172 bytes&amp;nbsp;of memory. Depending on the platform you will choose you should reach out to Cisco to verify that your amount of ACEs will work out. In case you have a large ruleset (&amp;gt; 250000 ACEs using a platform like 5525-X) you shouldnt have any issues but the number of NAT/IPSec VPNs should also be considered to size correctly.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;There is no official document that I am aware of that lists maximum rules for ASA.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Nov 2016 17:25:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/maximum-rules-limit-on-5500-x-platforms/m-p/2969527#M144549</guid>
      <dc:creator>Oliver Kaiser</dc:creator>
      <dc:date>2016-11-29T17:25:17Z</dc:date>
    </item>
    <item>
      <title>Hi There,</title>
      <link>https://community.cisco.com/t5/network-security/maximum-rules-limit-on-5500-x-platforms/m-p/2969528#M144550</link>
      <description>&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Hi There,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks for the reply.&lt;/P&gt;
&lt;P&gt;We are having major challenges in getting the configuration migrated from checkpoint (1780 odd ACLs with 0.2 million lines of rules), After configuring the access-group command, it has prompted as insufficient memory to install the rule and memory utilization has reached to 99%.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Is there any optimizing tool avaliable for the migration to give lesser performance issue since the ASA 5545-X is now going to put in production segment very soon.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks &amp;amp; Regards,&lt;/P&gt;
&lt;P&gt;Yogesh Madhekar&lt;/P&gt;</description>
      <pubDate>Wed, 30 Nov 2016 17:51:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/maximum-rules-limit-on-5500-x-platforms/m-p/2969528#M144550</guid>
      <dc:creator>ymadheka</dc:creator>
      <dc:date>2016-11-30T17:51:18Z</dc:date>
    </item>
    <item>
      <title>I was able to find more</title>
      <link>https://community.cisco.com/t5/network-security/maximum-rules-limit-on-5500-x-platforms/m-p/2969529#M144552</link>
      <description>&lt;P&gt;I was able to find more information on ACL recommended maximums in a cisco live session titled "Maximizing Firewall Performance". (2015)&lt;/P&gt;
&lt;P&gt;&lt;IMG width="684" height="91" alt="" src="https://community.cisco.com/legacyfs/online/attachments/discussion/acl-max.png" /&gt;&lt;/P&gt;
&lt;P&gt;Based on your platform you should be able to handle 200.000 ACEs. To verify your current number of ACE please execute the following command and post the output:&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;ASA# show access-list | include elements&lt;/PRE&gt;
&lt;P&gt;Depending on your output (count &amp;lt; 200k) please execute the following commands and&amp;nbsp;post the output&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;ASA# show version&lt;BR /&gt;ASA# show memory&lt;BR /&gt;ASA# show memory detail&lt;BR /&gt;ASA# show memory app-cache&lt;BR /&gt;ASA# show resource usage&lt;BR /&gt;ASA# show resource usage detail&lt;BR /&gt;ASA# show traffic&lt;BR /&gt;ASA# show blocks&lt;BR /&gt;ASA# show cpu core&lt;BR /&gt;ASA# show cpu detail&lt;/PRE&gt;</description>
      <pubDate>Wed, 30 Nov 2016 18:36:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/maximum-rules-limit-on-5500-x-platforms/m-p/2969529#M144552</guid>
      <dc:creator>Oliver Kaiser</dc:creator>
      <dc:date>2016-11-30T18:36:20Z</dc:date>
    </item>
    <item>
      <title>Will arrange the same and</title>
      <link>https://community.cisco.com/t5/network-security/maximum-rules-limit-on-5500-x-platforms/m-p/2969530#M144554</link>
      <description>&lt;P&gt;Will arrange the same and post here once data is available.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks &amp;amp; Regards,&lt;/P&gt;
&lt;P&gt;Yogesh Madhekar&lt;/P&gt;</description>
      <pubDate>Wed, 30 Nov 2016 18:53:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/maximum-rules-limit-on-5500-x-platforms/m-p/2969530#M144554</guid>
      <dc:creator>ymadheka</dc:creator>
      <dc:date>2016-11-30T18:53:49Z</dc:date>
    </item>
  </channel>
</rss>

