<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PIX Access Lists in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-access-lists/m-p/311971#M555793</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes you should put the more busy ones in the beginning.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;By the way there are two interesting features for access-list.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1.) Turbo access-list &lt;/P&gt;&lt;P&gt;TurboACL is a feature introduced with PIX Firewall version 6.2 that improves the average search time for access control lists containing a large number of entries. The TurboACL feature causes the PIX Firewall to compile tables for ACLs and this improves searching of long ACLs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[no] access-list compiled&lt;/P&gt;&lt;P&gt;[no] access-list &lt;ID&gt; compiled&lt;/ID&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;See: &lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/sw/secursw/ps2120/products_configuration_guide_chapter09186a00800eb721.html#wp1034390" target="_blank"&gt;http://www.cisco.com/en/US/products/sw/secursw/ps2120/products_configuration_guide_chapter09186a00800eb721.html#wp1034390&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2.) You can add access-list with a &lt;LINE&gt; statement, see eample:&lt;/LINE&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[no] access-list &lt;ID&gt; [line &lt;LINE-NUM&gt;] deny|permit ...&lt;/LINE-NUM&gt;&lt;/ID&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sincerely&lt;/P&gt;&lt;P&gt;Patrick&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 27 Oct 2004 15:16:44 GMT</pubDate>
    <dc:creator>Patrick Iseli</dc:creator>
    <dc:date>2004-10-27T15:16:44Z</dc:date>
    <item>
      <title>PIX Access Lists</title>
      <link>https://community.cisco.com/t5/network-security/pix-access-lists/m-p/311970#M555790</link>
      <description>&lt;P&gt;I finally got around to changing my conduits to access list entries. Should I adjust the order of the access list entries, keeping the busy entries first in line? My assumption is that the access list group is queried in order, similar to an IOS driven device. Thanks for the input.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 07:42:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-access-lists/m-p/311970#M555790</guid>
      <dc:creator>jeff.carr</dc:creator>
      <dc:date>2020-02-21T07:42:30Z</dc:date>
    </item>
    <item>
      <title>Re: PIX Access Lists</title>
      <link>https://community.cisco.com/t5/network-security/pix-access-lists/m-p/311971#M555793</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes you should put the more busy ones in the beginning.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;By the way there are two interesting features for access-list.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1.) Turbo access-list &lt;/P&gt;&lt;P&gt;TurboACL is a feature introduced with PIX Firewall version 6.2 that improves the average search time for access control lists containing a large number of entries. The TurboACL feature causes the PIX Firewall to compile tables for ACLs and this improves searching of long ACLs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[no] access-list compiled&lt;/P&gt;&lt;P&gt;[no] access-list &lt;ID&gt; compiled&lt;/ID&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;See: &lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/sw/secursw/ps2120/products_configuration_guide_chapter09186a00800eb721.html#wp1034390" target="_blank"&gt;http://www.cisco.com/en/US/products/sw/secursw/ps2120/products_configuration_guide_chapter09186a00800eb721.html#wp1034390&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2.) You can add access-list with a &lt;LINE&gt; statement, see eample:&lt;/LINE&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[no] access-list &lt;ID&gt; [line &lt;LINE-NUM&gt;] deny|permit ...&lt;/LINE-NUM&gt;&lt;/ID&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sincerely&lt;/P&gt;&lt;P&gt;Patrick&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Oct 2004 15:16:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-access-lists/m-p/311971#M555793</guid>
      <dc:creator>Patrick Iseli</dc:creator>
      <dc:date>2004-10-27T15:16:44Z</dc:date>
    </item>
    <item>
      <title>Re: PIX Access Lists</title>
      <link>https://community.cisco.com/t5/network-security/pix-access-lists/m-p/311972#M555798</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Excellent.&lt;/P&gt;&lt;P&gt;Thanks for the response, and for the info on 'TurboACL' and 'add ACL with line num'. Will come in handy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jeff&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Oct 2004 15:43:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-access-lists/m-p/311972#M555798</guid>
      <dc:creator>jeff.carr</dc:creator>
      <dc:date>2004-10-27T15:43:39Z</dc:date>
    </item>
  </channel>
</rss>

