<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: object-group network limit in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/object-group-network-limit/m-p/824640#M959529</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;On a Pix535 with 256MB of RAM, I tried to &lt;/P&gt;&lt;P&gt;jam in about 250,000 lines in the ACL and the&lt;/P&gt;&lt;P&gt;Pix blew up, and this pix is running version&lt;/P&gt;&lt;P&gt;7.x code.  The reality is not in the&lt;/P&gt;&lt;P&gt;config but how much acl it will translate&lt;/P&gt;&lt;P&gt;into when do you "show access-list".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Remember, you can have nested group within&lt;/P&gt;&lt;P&gt;group.  That's where the trouble begin.&lt;/P&gt;&lt;P&gt;Another thing to remember is that the or ASA&lt;/P&gt;&lt;P&gt;is an flash appliance so there are limitations&lt;/P&gt;&lt;P&gt;to what it can and can not do.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 04 Dec 2007 17:15:03 GMT</pubDate>
    <dc:creator>kevin.jones1</dc:creator>
    <dc:date>2007-12-04T17:15:03Z</dc:date>
    <item>
      <title>object-group network limit</title>
      <link>https://community.cisco.com/t5/network-security/object-group-network-limit/m-p/824637#M959524</link>
      <description>&lt;P&gt;Does anybody know if there is a limit on the total number of network-objects that can belong to a single network object-group? ASA 5520 8.0.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 11:38:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/object-group-network-limit/m-p/824637#M959524</guid>
      <dc:creator>gmillerarmt</dc:creator>
      <dc:date>2019-03-11T11:38:12Z</dc:date>
    </item>
    <item>
      <title>Re: object-group network limit</title>
      <link>https://community.cisco.com/t5/network-security/object-group-network-limit/m-p/824638#M959525</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;here's my best guess.  I don't believe it has to do with object-grouping itself.  My guess is it's more a limit of the ACL's.  I believe the following shows the number of acceptable entries in an ACL:&lt;/P&gt;&lt;P&gt;asa(config)# access-list outside_acl line ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;configure mode commands/options:&lt;/P&gt;&lt;P&gt;  &amp;lt;1-2147483647&amp;gt;  Line-number&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;so maybe 2,147,483,647 entires per ACL?  keep in mind, just because using object-groups reduces the number of ACE's entered, all the ACE's are still there if you use the 'show access-list' command.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 03 Dec 2007 19:32:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/object-group-network-limit/m-p/824638#M959525</guid>
      <dc:creator>srue</dc:creator>
      <dc:date>2007-12-03T19:32:08Z</dc:date>
    </item>
    <item>
      <title>Re: object-group network limit</title>
      <link>https://community.cisco.com/t5/network-security/object-group-network-limit/m-p/824639#M959527</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ah. See, what I am trying to do is limit access to external services by a geoIPlocator script. Standard stuff w/ htaccess, iptables, and to build dynamically but I have never done this on an ASA. I want to refresh a network object group with about 34000 network objects monthly and corresponding ACL. So, if there isn't a hard limit on the number of network objects that leaves me about 63000 access lists that can be created with that specific object-group. If I follow what you are sayingâ&amp;#128;¦&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 03 Dec 2007 19:49:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/object-group-network-limit/m-p/824639#M959527</guid>
      <dc:creator>gmillerarmt</dc:creator>
      <dc:date>2007-12-03T19:49:13Z</dc:date>
    </item>
    <item>
      <title>Re: object-group network limit</title>
      <link>https://community.cisco.com/t5/network-security/object-group-network-limit/m-p/824640#M959529</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;On a Pix535 with 256MB of RAM, I tried to &lt;/P&gt;&lt;P&gt;jam in about 250,000 lines in the ACL and the&lt;/P&gt;&lt;P&gt;Pix blew up, and this pix is running version&lt;/P&gt;&lt;P&gt;7.x code.  The reality is not in the&lt;/P&gt;&lt;P&gt;config but how much acl it will translate&lt;/P&gt;&lt;P&gt;into when do you "show access-list".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Remember, you can have nested group within&lt;/P&gt;&lt;P&gt;group.  That's where the trouble begin.&lt;/P&gt;&lt;P&gt;Another thing to remember is that the or ASA&lt;/P&gt;&lt;P&gt;is an flash appliance so there are limitations&lt;/P&gt;&lt;P&gt;to what it can and can not do.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Dec 2007 17:15:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/object-group-network-limit/m-p/824640#M959529</guid>
      <dc:creator>kevin.jones1</dc:creator>
      <dc:date>2007-12-04T17:15:03Z</dc:date>
    </item>
    <item>
      <title>Re: object-group network limit</title>
      <link>https://community.cisco.com/t5/network-security/object-group-network-limit/m-p/824641#M959530</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just to add to kevin's point. On a FWSM there is a command to show the acl count in the hardware "sh np x ???". Talk to someone in TAC to find an equivalent command for ASA. That is a very useful command if you are worried about the scalability limits.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Satya&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Dec 2007 17:52:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/object-group-network-limit/m-p/824641#M959530</guid>
      <dc:creator>sbaddipu</dc:creator>
      <dc:date>2007-12-04T17:52:35Z</dc:date>
    </item>
    <item>
      <title>Re: object-group network limit</title>
      <link>https://community.cisco.com/t5/network-security/object-group-network-limit/m-p/824642#M959531</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Satya&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm not sure that would work because the limits on the FWSM are hard limits imposed by the hardware architecture whereas the limits on the pix boxes are soft limits ie. limits imposed by cpu/memory etc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Dec 2007 18:23:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/object-group-network-limit/m-p/824642#M959531</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2007-12-04T18:23:34Z</dc:date>
    </item>
    <item>
      <title>Re: object-group network limit</title>
      <link>https://community.cisco.com/t5/network-security/object-group-network-limit/m-p/824643#M959532</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I tried to load a 515R, running 7.2.2, with just the network objects, no ACLs, and received nothing but memory allocation errors. The device was pretty much dead. I would receive memory allocation errors and the device would hang intermittently when just pinging it. &lt;/P&gt;&lt;P&gt;I upgraded the device to 8.0.3 and after loading up the 34000 network objects, the pix actually worked. None of the random memory allocation errors, the device didn't hang, and actually passed traffic. The problem came when i actually tried to create an ACL with the object-group, that's where I received memory allocation errors. But I believe that's just because I used all of the available memory.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Used memory reported after creating an ACL w/ object-group:        62007904 bytes (92%))&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What's worse it looks like the pix allocated the memory, failed on creating the access-list and didn't give the memory back up.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Used memory before trying to create an ACL w/ object-group:        55402880 bytes (83%)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And with only 16MB of flash, I have a feeling,there probably isn't enough room to save the config once the ACLs are made with the corresponding object-groups.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Not having modified the ASA as extensively as the PIX I would assume that it will have the same issues with processing a higher number of network-objects and ACLs. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Should I forget trying this on the ASA/PIX and move to implement this on the edge routers?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Dec 2007 17:11:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/object-group-network-limit/m-p/824643#M959532</guid>
      <dc:creator>gmillerarmt</dc:creator>
      <dc:date>2007-12-05T17:11:57Z</dc:date>
    </item>
  </channel>
</rss>

