<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic FWSM ACL Commit - Outage? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fwsm-acl-commit-outage/m-p/2000757#M400759</link>
    <description>&lt;P&gt;Hello Folks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope someone can share any experiences they have with ACL changes on FWSM and what impact that has on the traffic going though the FWSM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scenario I am facing at the moment, let me build the picture using examples;&lt;/P&gt;&lt;P&gt;----&lt;/P&gt;&lt;P&gt;Current Setup&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;VLANs&lt;/P&gt;&lt;P&gt;100,101,102,103,200,201,202 - All going through the CSM then FWSM with 50k ACL count.&lt;/P&gt;&lt;P&gt;----&lt;/P&gt;&lt;P&gt;New Setup&lt;/P&gt;&lt;P&gt;VLANs&lt;/P&gt;&lt;P&gt;100,101,102,103 and 200 stay the same, CSM and FWSM path.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;201 and 203 - bypass CSM.&lt;/P&gt;&lt;P&gt;----&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;While 201 and 203 are being removed, we will offcourse expect an outage on those VLANS until the bypass is complete.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;for the other VLANs, what impact will they see when this is taking place? we need to commit access-list, while this is taking place &lt;A href="http://www.cisco.com/en/US/docs/security/fwsm/fwsm22/configuration/guide/mngacl.html#wp1245596" target="_blank"&gt;Cisco state&lt;/A&gt; that &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"Large ACLs of approximately 60K ACEs can take 3 to 4 minutes to commit, depending on the size" &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have 50k of rules, while this recalculation is taking place, what is the impact on the traffic from on the VLANs we are not touching? I have conflicting reports from our firewall guys who say because the firewall will be busy recompling the rules, there will brief disruptions in all traffic passing the FWSM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any one here who has experience with making large changes to the ACL and if so what was the impact on the network? we have 100s of production servers in this network and it would be good to get some idea of what might happen while the firewall is busy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any input appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 23:42:52 GMT</pubDate>
    <dc:creator>xusenator</dc:creator>
    <dc:date>2019-03-11T23:42:52Z</dc:date>
    <item>
      <title>FWSM ACL Commit - Outage?</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-acl-commit-outage/m-p/2000757#M400759</link>
      <description>&lt;P&gt;Hello Folks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope someone can share any experiences they have with ACL changes on FWSM and what impact that has on the traffic going though the FWSM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scenario I am facing at the moment, let me build the picture using examples;&lt;/P&gt;&lt;P&gt;----&lt;/P&gt;&lt;P&gt;Current Setup&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;VLANs&lt;/P&gt;&lt;P&gt;100,101,102,103,200,201,202 - All going through the CSM then FWSM with 50k ACL count.&lt;/P&gt;&lt;P&gt;----&lt;/P&gt;&lt;P&gt;New Setup&lt;/P&gt;&lt;P&gt;VLANs&lt;/P&gt;&lt;P&gt;100,101,102,103 and 200 stay the same, CSM and FWSM path.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;201 and 203 - bypass CSM.&lt;/P&gt;&lt;P&gt;----&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;While 201 and 203 are being removed, we will offcourse expect an outage on those VLANS until the bypass is complete.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;for the other VLANs, what impact will they see when this is taking place? we need to commit access-list, while this is taking place &lt;A href="http://www.cisco.com/en/US/docs/security/fwsm/fwsm22/configuration/guide/mngacl.html#wp1245596" target="_blank"&gt;Cisco state&lt;/A&gt; that &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"Large ACLs of approximately 60K ACEs can take 3 to 4 minutes to commit, depending on the size" &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have 50k of rules, while this recalculation is taking place, what is the impact on the traffic from on the VLANs we are not touching? I have conflicting reports from our firewall guys who say because the firewall will be busy recompling the rules, there will brief disruptions in all traffic passing the FWSM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any one here who has experience with making large changes to the ACL and if so what was the impact on the network? we have 100s of production servers in this network and it would be good to get some idea of what might happen while the firewall is busy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any input appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 23:42:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-acl-commit-outage/m-p/2000757#M400759</guid>
      <dc:creator>xusenator</dc:creator>
      <dc:date>2019-03-11T23:42:52Z</dc:date>
    </item>
    <item>
      <title>FWSM ACL Commit - Outage?</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-acl-commit-outage/m-p/2000758#M400760</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you enabled ACL optimization. If not, have a look at this and enable it&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/fwsm/fwsm40/configuration/guide/traffc_f.html#wp1068726"&gt;http://www.cisco.com/en/US/docs/security/fwsm/fwsm40/configuration/guide/traffc_f.html#wp1068726&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Zubair&lt;/P&gt;&lt;P&gt;-Pls rate if post was useful-&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Aug 2012 23:29:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-acl-commit-outage/m-p/2000758#M400760</guid>
      <dc:creator>zujalal</dc:creator>
      <dc:date>2012-08-15T23:29:08Z</dc:date>
    </item>
    <item>
      <title>FWSM ACL Commit - Outage?</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-acl-commit-outage/m-p/2000759#M400762</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi zujalal,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are already using that feature to reduce the ammout of rules in the ACL, my question is mainly around what happens to the traffic in scenario where the firewall is very busy commiting rules, does it drop packets or anything like that?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;for example, what will it look like to a server that is connecting through the busy fwsm?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Aug 2012 00:26:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-acl-commit-outage/m-p/2000759#M400762</guid>
      <dc:creator>xusenator</dc:creator>
      <dc:date>2012-08-16T00:26:05Z</dc:date>
    </item>
    <item>
      <title>FWSM ACL Commit - Outage?</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-acl-commit-outage/m-p/2000760#M400764</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are you using manual commit or auto-commit. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Aug 2012 01:24:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-acl-commit-outage/m-p/2000760#M400764</guid>
      <dc:creator>zujalal</dc:creator>
      <dc:date>2012-08-16T01:24:35Z</dc:date>
    </item>
    <item>
      <title>FWSM ACL Commit - Outage?</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-acl-commit-outage/m-p/2000761#M400765</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Manual commit is what we will be using given the ammount of changes we need to do.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Aug 2012 07:32:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-acl-commit-outage/m-p/2000761#M400765</guid>
      <dc:creator>xusenator</dc:creator>
      <dc:date>2012-08-16T07:32:17Z</dc:date>
    </item>
  </channel>
</rss>

