<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CSA 5.0: Complexity Exceeds Maximum in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/csa-5-0-complexity-exceeds-maximum/m-p/912764#M85306</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Response from Cisco Tech Support.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This happens when there are too many literals in the ruleset. A literal is anything defined in a fileset. For example, foo.exe is 1 literal. foo.exe, foo2.exe are two literals. To reduce the literals and thus generate rules successfully, one needs to wildcard and generalize when possible. So foo*.exe would change the literals to 1 from 2 (from foo.exe and foo2.exe for example). The maximum literals is 7500.&lt;/P&gt;&lt;P&gt;Basically, for a little insight into why the value of 7500 was selected. The default rule sets have a complexity of no more than 2500. The internal Cisco Policy is not even double that value. So triple the default was selected to allow plenty of rule for customization.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you exceed 7500 literals, rule generation would be extremely slow and would most likely timeout.  &lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;As a rule of thumb:  always wildcard where possible.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 12 Nov 2007 20:14:35 GMT</pubDate>
    <dc:creator>eaglesecure</dc:creator>
    <dc:date>2007-11-12T20:14:35Z</dc:date>
    <item>
      <title>CSA 5.0: Complexity Exceeds Maximum</title>
      <link>https://community.cisco.com/t5/network-security/csa-5-0-complexity-exceeds-maximum/m-p/912763#M85304</link>
      <description>&lt;P&gt;Recently I was tuning out some false positives and was unable to generate the rules due to  a complexity of greater than 7500 exceeds maximum of 7500. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I searched the forum and found out the there is a limit to the number of complexity points set at 7500.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The post says to remove old Rules/Groups and Rule Modules or try condesing all of those.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have gone through and made the changes that would put me under the limit.  But when I attempt to generate these rules to move under the limit I receive the same warning.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How can I get under the limit if I cannot generate any changes?&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 10:52:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csa-5-0-complexity-exceeds-maximum/m-p/912763#M85304</guid>
      <dc:creator>eaglesecure</dc:creator>
      <dc:date>2019-03-10T10:52:14Z</dc:date>
    </item>
    <item>
      <title>Re: CSA 5.0: Complexity Exceeds Maximum</title>
      <link>https://community.cisco.com/t5/network-security/csa-5-0-complexity-exceeds-maximum/m-p/912764#M85306</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Response from Cisco Tech Support.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This happens when there are too many literals in the ruleset. A literal is anything defined in a fileset. For example, foo.exe is 1 literal. foo.exe, foo2.exe are two literals. To reduce the literals and thus generate rules successfully, one needs to wildcard and generalize when possible. So foo*.exe would change the literals to 1 from 2 (from foo.exe and foo2.exe for example). The maximum literals is 7500.&lt;/P&gt;&lt;P&gt;Basically, for a little insight into why the value of 7500 was selected. The default rule sets have a complexity of no more than 2500. The internal Cisco Policy is not even double that value. So triple the default was selected to allow plenty of rule for customization.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you exceed 7500 literals, rule generation would be extremely slow and would most likely timeout.  &lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;As a rule of thumb:  always wildcard where possible.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Nov 2007 20:14:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csa-5-0-complexity-exceeds-maximum/m-p/912764#M85306</guid>
      <dc:creator>eaglesecure</dc:creator>
      <dc:date>2007-11-12T20:14:35Z</dc:date>
    </item>
  </channel>
</rss>

