<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Rules for host.domain.com have complexity 7525 which exceeds in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/rules-for-host-domain-com-have-complexity-7525-which-exceeds/m-p/640378#M87628</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;How many do rules do you have total?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 06 Feb 2007 21:52:16 GMT</pubDate>
    <dc:creator>tsteger1</dc:creator>
    <dc:date>2007-02-06T21:52:16Z</dc:date>
    <item>
      <title>Rules for host.domain.com have complexity 7525 which exceeds</title>
      <link>https://community.cisco.com/t5/network-security/rules-for-host-domain-com-have-complexity-7525-which-exceeds/m-p/640375#M87622</link>
      <description>&lt;P&gt;Has anyone seen this issue in CSA 5.0 when generating rules?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rules for host.domain.com  have complexity 7525 which exceeds the maximum of 7500 &lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 10:27:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/rules-for-host-domain-com-have-complexity-7525-which-exceeds/m-p/640375#M87622</guid>
      <dc:creator>taylr</dc:creator>
      <dc:date>2019-03-10T10:27:12Z</dc:date>
    </item>
    <item>
      <title>Re: Rules for host.domain.com have complexity 7525 which exceeds</title>
      <link>https://community.cisco.com/t5/network-security/rules-for-host-domain-com-have-complexity-7525-which-exceeds/m-p/640376#M87624</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No, but how many rules do you have or how many rule changes were pending?  &lt;/P&gt;&lt;P&gt;CSA won't generate rules in some conditions.  Too short of a polling interval is one.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Perhaps there is a maximum rule change or rule limit as well.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Feb 2007 00:59:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/rules-for-host-domain-com-have-complexity-7525-which-exceeds/m-p/640376#M87624</guid>
      <dc:creator>tsteger1</dc:creator>
      <dc:date>2007-02-06T00:59:18Z</dc:date>
    </item>
    <item>
      <title>Re: Rules for host.domain.com have complexity 7525 which exceeds</title>
      <link>https://community.cisco.com/t5/network-security/rules-for-host-domain-com-have-complexity-7525-which-exceeds/m-p/640377#M87626</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There are 52 rules pending.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Feb 2007 21:00:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/rules-for-host-domain-com-have-complexity-7525-which-exceeds/m-p/640377#M87626</guid>
      <dc:creator>taylr</dc:creator>
      <dc:date>2007-02-06T21:00:02Z</dc:date>
    </item>
    <item>
      <title>Re: Rules for host.domain.com have complexity 7525 which exceeds</title>
      <link>https://community.cisco.com/t5/network-security/rules-for-host-domain-com-have-complexity-7525-which-exceeds/m-p/640378#M87628</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;How many do rules do you have total?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Feb 2007 21:52:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/rules-for-host-domain-com-have-complexity-7525-which-exceeds/m-p/640378#M87628</guid>
      <dc:creator>tsteger1</dc:creator>
      <dc:date>2007-02-06T21:52:16Z</dc:date>
    </item>
    <item>
      <title>Re: Rules for host.domain.com have complexity 7525 which exceeds</title>
      <link>https://community.cisco.com/t5/network-security/rules-for-host-domain-com-have-complexity-7525-which-exceeds/m-p/640379#M87630</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, there is a complexity limit of 7500. We hit it a few months ago. What we did to fix it was to go through all the rules and wild card where we could and combine rules where we could. There is a value for each rule module/rule/app class/network address set/etc. and each line in each of those. So for example if you have an app class with @program files\abc.exe and **\temp\abc.exe that counts as 2 complexity points. Our biggest issue is network address sets. Its an ongoing battle. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cisco says its there so the hosts don't have too much information to process and slow the machine down. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Shelly&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Feb 2007 19:22:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/rules-for-host-domain-com-have-complexity-7525-which-exceeds/m-p/640379#M87630</guid>
      <dc:creator>shelly.kane</dc:creator>
      <dc:date>2007-02-22T19:22:36Z</dc:date>
    </item>
    <item>
      <title>Re: Rules for host.domain.com have complexity 7525 which exceeds</title>
      <link>https://community.cisco.com/t5/network-security/rules-for-host-domain-com-have-complexity-7525-which-exceeds/m-p/640380#M87631</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Shelly, thanks for the good information.   &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We delete everything associated with OSs we will never use (Linux, Solaris).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After each upgrade, everything is deleted if it's not needed and associated with new items if it is.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This keeps the MC pretty lean and rule generation is much faster.  We have 388 rules on a 4.0.3 MC and 690 on a 5.1.  All told there are 794 items on the 4.0.3 MC and 2121 items on the 5.1 MC.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tom &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Feb 2007 20:08:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/rules-for-host-domain-com-have-complexity-7525-which-exceeds/m-p/640380#M87631</guid>
      <dc:creator>tsteger1</dc:creator>
      <dc:date>2007-02-22T20:08:57Z</dc:date>
    </item>
  </channel>
</rss>

