<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FWSM memory partitions in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fwsm-memory-partitions/m-p/1301197#M785093</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Looks like you would have to move this big context to a separate firewall. Have you looked at the ASA5580s?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/products/ps6120/prod_models_comparison.html"&gt;http://www.cisco.com/en/US/products/ps6120/prod_models_comparison.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 04 Dec 2009 13:56:39 GMT</pubDate>
    <dc:creator>Kureli Sankar</dc:creator>
    <dc:date>2009-12-04T13:56:39Z</dc:date>
    <item>
      <title>FWSM memory partitions</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-memory-partitions/m-p/1301193#M785041</link>
      <description>&lt;INPUT id="gwProxy" type="hidden" /&gt;&lt;!--Session data--&gt;&lt;INPUT id="jsProxy" onclick="" type="hidden" /&gt;&lt;DIV id="refHTML"&gt; &lt;/DIV&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a questions on FWSM memory partition. I understand that there are 12 memory partitions and we can configure how many partitions we need.&lt;/P&gt;&lt;P&gt;If i set the number of partition to 6, then each partition will have more resources compared to if i set the number of partitions to 12.&lt;/P&gt;&lt;P&gt;Can i just set the number of partition to 1, then in this case, i have one big memory partition which all the contexts i created will use.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My client (running 3.X) has 6 partitions of equal size. One of the partition is running out of resource and the other partitions still have plenty of resources. I undertand that 4.x has some enhancement on resource allocation. I am just thinking if it might be easier just to have one large partition and any context just use that pool of resrouces. In this way, it will keep things simple..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has anyone tried this before? Anything i should take note of if i do this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Eng Wee&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;INPUT id="gwProxy" type="hidden" /&gt;&lt;!--Session data--&gt;&lt;INPUT id="jsProxy" onclick="" type="hidden" /&gt;&lt;DIV id="refHTML"&gt; &lt;/DIV&gt;</description>
      <pubDate>Mon, 11 Mar 2019 16:44:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-memory-partitions/m-p/1301193#M785041</guid>
      <dc:creator>e-chuah</dc:creator>
      <dc:date>2019-03-11T16:44:31Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM memory partitions</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-memory-partitions/m-p/1301194#M785049</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;e-chuah wrote:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;INPUT id="gwProxy" type="hidden" /&gt;&lt;INPUT id="jsProxy" type="hidden" /&gt;&lt;DIV id="refHTML"&gt; &lt;/DIV&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a questions on FWSM memory partition. I understand that there are 12 memory partitions and we can configure how many partitions we need.&lt;/P&gt;&lt;P&gt;If i set the number of partition to 6, then each partition will have more resources compared to if i set the number of partitions to 12.&lt;/P&gt;&lt;P&gt;Can i just set the number of partition to 1, then in this case, i have one big memory partition which all the contexts i created will use.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My client (running 3.X) has 6 partitions of equal size. One of the partition is running out of resource and the other partitions still have plenty of resources. I undertand that 4.x has some enhancement on resource allocation. I am just thinking if it might be easier just to have one large partition and any context just use that pool of resrouces. In this way, it will keep things simple..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has anyone tried this before? Anything i should take note of if i do this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Eng Wee&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;INPUT id="gwProxy" type="hidden" /&gt;&lt;INPUT id="jsProxy" type="hidden" /&gt;&lt;DIV id="refHTML"&gt; &lt;/DIV&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Eng&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can do this but i wouldn't recommend it. The whole idea of using memory partitions is to protect virtual firewalls from each other. If you have one big partition with all contexts in and one context consumes all resources then all contexts suffer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Dec 2009 11:46:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-memory-partitions/m-p/1301194#M785049</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2009-12-02T11:46:18Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM memory partitions</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-memory-partitions/m-p/1301195#M785057</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;FWSM 4.x&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE&gt;Total Partitions&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ACLs&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;12&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;19219&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;11&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;20821&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;10&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;22714&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;9&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;24985&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;8&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;27761&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;7&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;31232&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;6&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;35693&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;5&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;41642&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;4&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;49971&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;3&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;62464&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;83285&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;124928&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;There is also acl optimization in 4.x. &lt;BR /&gt;&lt;A href="http://www.cisco.com/en/US/prod/collateral/modules/ps2706/product_bulletin_c25-478751.html" target="_blank"&gt;http://www.cisco.com/en/US/prod/collateral/modules/ps2706/product_bulletin_c25-478751.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN class="content"&gt;&lt;/SPAN&gt;&lt;BR /&gt;I agree with Jon. May be you can go to 3 partitions and point all the smaller contexts to one partition and give &lt;BR /&gt;the bigger context its own partition.&lt;BR /&gt;&lt;BR /&gt;-KS&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/PRE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Dec 2009 14:49:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-memory-partitions/m-p/1301195#M785057</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2009-12-02T14:49:52Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM memory partitions</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-memory-partitions/m-p/1301196#M785069</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;kusankar &amp;amp; Jon,&amp;nbsp; Thanks for the reply. I managed to get hold of a FWSM and downloaded 4.x to test.&amp;nbsp; With 1 partition, you get 124928 rules in total excluding the backup tree with 2 partitions, you get 166570 rules in total excluding the backup tree. with 12 partitions, you get 230628 rules in total excluding the backup tree&amp;nbsp; This is because of the backup tree partition which is equivalent to the size of the biggest partition. So even with one partition, it doesn't mean you can have more context as the total number of rules are also reduced.&amp;nbsp;&amp;nbsp; Rgds Eng Wee&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 04 Dec 2009 11:01:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-memory-partitions/m-p/1301196#M785069</guid>
      <dc:creator>e-chuah</dc:creator>
      <dc:date>2009-12-04T11:01:50Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM memory partitions</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-memory-partitions/m-p/1301197#M785093</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Looks like you would have to move this big context to a separate firewall. Have you looked at the ASA5580s?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/products/ps6120/prod_models_comparison.html"&gt;http://www.cisco.com/en/US/products/ps6120/prod_models_comparison.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 04 Dec 2009 13:56:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-memory-partitions/m-p/1301197#M785093</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2009-12-04T13:56:39Z</dc:date>
    </item>
  </channel>
</rss>

