<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Maximum ACL rules in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/maximum-acl-rules/m-p/1035246#M895346</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There is no maximum number of ACL entries which we can accommodate in ASA. It depends upon the DRAM size.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Syed Iftekhar Ahmed&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 08 Oct 2008 17:28:37 GMT</pubDate>
    <dc:creator>Syed Iftekhar Ahmed</dc:creator>
    <dc:date>2008-10-08T17:28:37Z</dc:date>
    <item>
      <title>Maximum ACL rules</title>
      <link>https://community.cisco.com/t5/network-security/maximum-acl-rules/m-p/1035245#M895344</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is anybody aware of the maxinum number of access list rules an ASA can take. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 13:54:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/maximum-acl-rules/m-p/1035245#M895344</guid>
      <dc:creator>innetsecwork</dc:creator>
      <dc:date>2019-03-11T13:54:46Z</dc:date>
    </item>
    <item>
      <title>Re: Maximum ACL rules</title>
      <link>https://community.cisco.com/t5/network-security/maximum-acl-rules/m-p/1035246#M895346</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There is no maximum number of ACL entries which we can accommodate in ASA. It depends upon the DRAM size.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Syed Iftekhar Ahmed&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Oct 2008 17:28:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/maximum-acl-rules/m-p/1035246#M895346</guid>
      <dc:creator>Syed Iftekhar Ahmed</dc:creator>
      <dc:date>2008-10-08T17:28:37Z</dc:date>
    </item>
    <item>
      <title>Re: Maximum ACL rules</title>
      <link>https://community.cisco.com/t5/network-security/maximum-acl-rules/m-p/1035247#M895348</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As your number of rules increases, the CPU load will increase as well.  While there is no hard and fast limit I have had experience with a PIX 535 becoming CPU bound due to the size of the ACLs applied coupled with the complicated NAT rules and hundreds of static routes.  In this case, the firewall would occasionally hit max CPU usage during peak traffic periods and start discarding packets.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Deleting ACL entries and cleaning up the config solved the issue in that situation.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Oct 2008 19:08:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/maximum-acl-rules/m-p/1035247#M895348</guid>
      <dc:creator>Matthew Warrick</dc:creator>
      <dc:date>2008-10-08T19:08:30Z</dc:date>
    </item>
    <item>
      <title>Re: Maximum ACL rules</title>
      <link>https://community.cisco.com/t5/network-security/maximum-acl-rules/m-p/1035248#M895349</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is my understanding that the ASA uses around 20KB for an Access List Entry (ACE). So, the number of ACE really depends on the memory on the chassis and other features that are you planning to enable.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Below is the data sheet for the ASA that has information on various ASA platforms and memory.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/prod/collateral/vpndevc/ps6032/ps6094/ps6120/product_data_sheet0900aecd802930c5.html" target="_blank"&gt;http://www.cisco.com/en/US/prod/collateral/vpndevc/ps6032/ps6094/ps6120/product_data_sheet0900aecd802930c5.html&lt;/A&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Arul&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;** Please rate all helpful posts **&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Oct 2008 19:46:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/maximum-acl-rules/m-p/1035248#M895349</guid>
      <dc:creator>ajagadee</dc:creator>
      <dc:date>2008-10-08T19:46:01Z</dc:date>
    </item>
    <item>
      <title>Re: Maximum ACL rules</title>
      <link>https://community.cisco.com/t5/network-security/maximum-acl-rules/m-p/1035249#M895350</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;adding to what has been said.  I have found that many customers don't use object groups which can reduce the size of the ACLs substantially. The best approach is to create object groups, remove ACL with not hits, place the entries that are hited the most on the top of the ACL ..  just my 20 cents &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Oct 2008 21:35:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/maximum-acl-rules/m-p/1035249#M895350</guid>
      <dc:creator>Fernando_Meza</dc:creator>
      <dc:date>2008-10-08T21:35:31Z</dc:date>
    </item>
    <item>
      <title>Maximum ACL rules</title>
      <link>https://community.cisco.com/t5/network-security/maximum-acl-rules/m-p/1035250#M895351</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, can you give me link for docs about ACLs processing?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It's interesting about object groups. Is there any processing docs and compare?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 02 Jun 2013 06:15:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/maximum-acl-rules/m-p/1035250#M895351</guid>
      <dc:creator>Mokeev.tel</dc:creator>
      <dc:date>2013-06-02T06:15:32Z</dc:date>
    </item>
    <item>
      <title>Maximum ACL rules</title>
      <link>https://community.cisco.com/t5/network-security/maximum-acl-rules/m-p/1035251#M895352</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Sergey,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have read somewhere that each element or ACL entry requires about 40-56 bytes but there is no limit specific as there is in the FWSM where is normal to get warnings if you have a huge amount on ACLs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would not consider normal or common on an ASA to have a problem regarding CPU/Memory due to ACL's. I have not seen it before&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that I could help&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 02 Jun 2013 07:26:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/maximum-acl-rules/m-p/1035251#M895352</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-06-02T07:26:11Z</dc:date>
    </item>
    <item>
      <title>Maximum ACL rules</title>
      <link>https://community.cisco.com/t5/network-security/maximum-acl-rules/m-p/1035252#M895353</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, Julio!&lt;/P&gt;&lt;P&gt;I'm glad to see you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does ASA do some optinization of ACLs?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I mean, will be there any difference if ACL lines with heavy traffic will be at lines from 1 to 10 or they will be at lines from 500 to 509?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 02 Jun 2013 07:40:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/maximum-acl-rules/m-p/1035252#M895353</guid>
      <dc:creator>Mokeev.tel</dc:creator>
      <dc:date>2013-06-02T07:40:15Z</dc:date>
    </item>
    <item>
      <title>Maximum ACL rules</title>
      <link>https://community.cisco.com/t5/network-security/maximum-acl-rules/m-p/1035253#M895354</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The optimization would be use object groups when possible so you can reduce the amount of ACL lines,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;Remember to rate all of the helpful posts, that is as important as a thanks&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 03 Jun 2013 16:19:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/maximum-acl-rules/m-p/1035253#M895354</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-06-03T16:19:10Z</dc:date>
    </item>
  </channel>
</rss>

