<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FTDs and ACE limit in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ftds-and-ace-limit/m-p/3990705#M934960</link>
    <description>&lt;P&gt;The recommended maximum AC Elements on ASA 5516-x running FTD is 125,000.&lt;/P&gt;
&lt;P&gt;I don't have a number for Firepower 2110 but for 2120 it is 75,000&lt;/P&gt;</description>
    <pubDate>Thu, 28 Nov 2019 11:55:09 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2019-11-28T11:55:09Z</dc:date>
    <item>
      <title>FTDs and ACE limit</title>
      <link>https://community.cisco.com/t5/network-security/ftds-and-ace-limit/m-p/3989494#M934958</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I've previously had problems with 5512-Xs running ASA having an ACE limit of 100K. Is ACE a relevant limit for 5516-Xs running FTD 6.4.0.4? What about FTD 2110? I've read somewhere the limit is 200K for ASA 5516-X running ASA code but nothing specific for FTD 5516-X.&lt;/P&gt;&lt;P&gt;The reason I ask is because I recently have had issues with two sets of 5516-Xs having just above 220K ACE entries for the main global access list generated by the FMC in the ASA code. I didn't think much of it at the time of the incidents but I'm starting to wonder.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Fredrik&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 17:43:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftds-and-ace-limit/m-p/3989494#M934958</guid>
      <dc:creator>hoffa2000</dc:creator>
      <dc:date>2020-02-21T17:43:28Z</dc:date>
    </item>
    <item>
      <title>Re: FTDs and ACE limit</title>
      <link>https://community.cisco.com/t5/network-security/ftds-and-ace-limit/m-p/3990705#M934960</link>
      <description>&lt;P&gt;The recommended maximum AC Elements on ASA 5516-x running FTD is 125,000.&lt;/P&gt;
&lt;P&gt;I don't have a number for Firepower 2110 but for 2120 it is 75,000&lt;/P&gt;</description>
      <pubDate>Thu, 28 Nov 2019 11:55:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftds-and-ace-limit/m-p/3990705#M934960</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2019-11-28T11:55:09Z</dc:date>
    </item>
    <item>
      <title>Re: FTDs and ACE limit</title>
      <link>https://community.cisco.com/t5/network-security/ftds-and-ace-limit/m-p/3990858#M934961</link>
      <description>&lt;P&gt;What Marvin said. Also, I would recommend reaching out to TAC as they can help you validate if you are indeed starting to reach and exceed the recommended limits. In addition, there are ways you can optimize your rules which will in turn reduce your ACL elements.&lt;/P&gt;
&lt;P&gt;I hope this helps!&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Nov 2019 17:04:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftds-and-ace-limit/m-p/3990858#M934961</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2019-11-28T17:04:56Z</dc:date>
    </item>
    <item>
      <title>Re: FTDs and ACE limit</title>
      <link>https://community.cisco.com/t5/network-security/ftds-and-ace-limit/m-p/4076954#M1069701</link>
      <description>&lt;P&gt;From Cisco Live BRKSEC-3455 (&lt;A href="https://www.ciscolive.com/c/dam/r/ciscolive/emea/docs/2020/pdf/BRKSEC-3455.pdf" target="_blank"&gt;https://www.ciscolive.com/c/dam/r/ciscolive/emea/docs/2020/pdf/BRKSEC-3455.pdf):&lt;/A&gt; Max Recommended AC element count limit is 50k for FPR 2110.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kr,&lt;/P&gt;&lt;P&gt;A&lt;/P&gt;</description>
      <pubDate>Thu, 30 Apr 2020 07:38:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftds-and-ace-limit/m-p/4076954#M1069701</guid>
      <dc:creator>askaerr</dc:creator>
      <dc:date>2020-04-30T07:38:17Z</dc:date>
    </item>
  </channel>
</rss>

