<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Does applying ACE's to VPN's on ASA slow the VPN down slight in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/does-applying-ace-s-to-vpn-s-on-asa-slow-the-vpn-down-slightly/m-p/985432#M918208</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The 'show access-list' will show you a hitcount irrespective of the 'log' keyword.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The log keyword goes one step further to generate syslogs whenever the ACE is matched.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 18 Jun 2008 13:40:38 GMT</pubDate>
    <dc:creator>Farrukh Haroon</dc:creator>
    <dc:date>2008-06-18T13:40:38Z</dc:date>
    <item>
      <title>Does applying ACE's to VPN's on ASA slow the VPN down slightly?</title>
      <link>https://community.cisco.com/t5/network-security/does-applying-ace-s-to-vpn-s-on-asa-slow-the-vpn-down-slightly/m-p/985423#M918177</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a Cisco ASA and a test site-to-site VPN and a test Cisco client VPN coming into it.  I had a rule which was just allow any any before on the outside interface to the inbound interface where the servers are.  But have now added many many rules to lockdown what users on the VPN can get to so just the servers and their ports required are open.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can this slow down the connection response to the user?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks &lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 13:00:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/does-applying-ace-s-to-vpn-s-on-asa-slow-the-vpn-down-slightly/m-p/985423#M918177</guid>
      <dc:creator>whiteford</dc:creator>
      <dc:date>2019-03-11T13:00:54Z</dc:date>
    </item>
    <item>
      <title>Re: Does applying ACE's to VPN's on ASA slow the VPN down slight</title>
      <link>https://community.cisco.com/t5/network-security/does-applying-ace-s-to-vpn-s-on-asa-slow-the-vpn-down-slightly/m-p/985424#M918179</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Assuming your entries are configured in an efficient way i.e making sure the most matching rules are at the top of the access list, there are no entries logging events unless you really need it, using group objects whenever applicable ..  etc.  It is most likely that the user will not even notice the difference. The approach you had followed is the correct from a security perspective.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope it helps ..  please rate helpfull posts &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Jun 2008 09:07:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/does-applying-ace-s-to-vpn-s-on-asa-slow-the-vpn-down-slightly/m-p/985424#M918179</guid>
      <dc:creator>Fernando_Meza</dc:creator>
      <dc:date>2008-06-18T09:07:05Z</dc:date>
    </item>
    <item>
      <title>Re: Does applying ACE's to VPN's on ASA slow the VPN down slight</title>
      <link>https://community.cisco.com/t5/network-security/does-applying-ace-s-to-vpn-s-on-asa-slow-the-vpn-down-slightly/m-p/985425#M918181</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This limited ammount of filtering should not cause any performance issues.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Jun 2008 09:54:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/does-applying-ace-s-to-vpn-s-on-asa-slow-the-vpn-down-slightly/m-p/985425#M918181</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2008-06-18T09:54:57Z</dc:date>
    </item>
    <item>
      <title>Re: Does applying ACE's to VPN's on ASA slow the VPN down slight</title>
      <link>https://community.cisco.com/t5/network-security/does-applying-ace-s-to-vpn-s-on-asa-slow-the-vpn-down-slightly/m-p/985426#M918187</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks, so it might be best I move the ACE's to the top of the outside list?  I have about 15 and I can simply use the ASDM to do this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Jun 2008 09:58:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/does-applying-ace-s-to-vpn-s-on-asa-slow-the-vpn-down-slightly/m-p/985426#M918187</guid>
      <dc:creator>whiteford</dc:creator>
      <dc:date>2008-06-18T09:58:28Z</dc:date>
    </item>
    <item>
      <title>Re: Does applying ACE's to VPN's on ASA slow the VPN down slight</title>
      <link>https://community.cisco.com/t5/network-security/does-applying-ace-s-to-vpn-s-on-asa-slow-the-vpn-down-slightly/m-p/985427#M918195</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It is a best practice to put ACEs for frequently occuring traffic like management traffic (routing,snmp etc) at the top of ACLs. I think this should be doable in ASDM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Jun 2008 10:11:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/does-applying-ace-s-to-vpn-s-on-asa-slow-the-vpn-down-slightly/m-p/985427#M918195</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2008-06-18T10:11:08Z</dc:date>
    </item>
    <item>
      <title>Re: Does applying ACE's to VPN's on ASA slow the VPN down slight</title>
      <link>https://community.cisco.com/t5/network-security/does-applying-ace-s-to-vpn-s-on-asa-slow-the-vpn-down-slightly/m-p/985428#M918198</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Great there is a nice copy and paste function in the ADSL &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Jun 2008 10:15:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/does-applying-ace-s-to-vpn-s-on-asa-slow-the-vpn-down-slightly/m-p/985428#M918198</guid>
      <dc:creator>whiteford</dc:creator>
      <dc:date>2008-06-18T10:15:44Z</dc:date>
    </item>
    <item>
      <title>Re: Does applying ACE's to VPN's on ASA slow the VPN down slight</title>
      <link>https://community.cisco.com/t5/network-security/does-applying-ace-s-to-vpn-s-on-asa-slow-the-vpn-down-slightly/m-p/985429#M918201</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;THanks guys, how can I also tell if the rules are being logged?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Jun 2008 12:46:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/does-applying-ace-s-to-vpn-s-on-asa-slow-the-vpn-down-slightly/m-p/985429#M918201</guid>
      <dc:creator>whiteford</dc:creator>
      <dc:date>2008-06-18T12:46:44Z</dc:date>
    </item>
    <item>
      <title>Re: Does applying ACE's to VPN's on ASA slow the VPN down slight</title>
      <link>https://community.cisco.com/t5/network-security/does-applying-ace-s-to-vpn-s-on-asa-slow-the-vpn-down-slightly/m-p/985430#M918204</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;on the CLI you can use&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show access-list&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASDM also has a similar field I think (8.x even has a real time one AFAIR).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Jun 2008 13:15:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/does-applying-ace-s-to-vpn-s-on-asa-slow-the-vpn-down-slightly/m-p/985430#M918204</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2008-06-18T13:15:15Z</dc:date>
    </item>
    <item>
      <title>Re: Does applying ACE's to VPN's on ASA slow the VPN down slight</title>
      <link>https://community.cisco.com/t5/network-security/does-applying-ace-s-to-vpn-s-on-asa-slow-the-vpn-down-slightly/m-p/985431#M918206</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I did a sh access-list - should there simply be a "log" at the end of each ACE?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Jun 2008 13:38:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/does-applying-ace-s-to-vpn-s-on-asa-slow-the-vpn-down-slightly/m-p/985431#M918206</guid>
      <dc:creator>whiteford</dc:creator>
      <dc:date>2008-06-18T13:38:48Z</dc:date>
    </item>
    <item>
      <title>Re: Does applying ACE's to VPN's on ASA slow the VPN down slight</title>
      <link>https://community.cisco.com/t5/network-security/does-applying-ace-s-to-vpn-s-on-asa-slow-the-vpn-down-slightly/m-p/985432#M918208</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The 'show access-list' will show you a hitcount irrespective of the 'log' keyword.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The log keyword goes one step further to generate syslogs whenever the ACE is matched.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Jun 2008 13:40:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/does-applying-ace-s-to-vpn-s-on-asa-slow-the-vpn-down-slightly/m-p/985432#M918208</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2008-06-18T13:40:38Z</dc:date>
    </item>
    <item>
      <title>Re: Does applying ACE's to VPN's on ASA slow the VPN down slight</title>
      <link>https://community.cisco.com/t5/network-security/does-applying-ace-s-to-vpn-s-on-asa-slow-the-vpn-down-slightly/m-p/985433#M918210</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Happs, I am getting hit counts, just popped onto the ASDM.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Jun 2008 13:42:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/does-applying-ace-s-to-vpn-s-on-asa-slow-the-vpn-down-slightly/m-p/985433#M918210</guid>
      <dc:creator>whiteford</dc:creator>
      <dc:date>2008-06-18T13:42:58Z</dc:date>
    </item>
  </channel>
</rss>

