cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements

Welcome to Cisco Firewalls Community


353
Views
0
Helpful
1
Replies
Beginner

How many objects can an ASA support?

We are currently running 8.3(2) and I'm just wondering how many network/host objects the device can support? and how big can an access-l get?

Cheers.

Everyone's tags (5)
1 REPLY 1
Engager

How many objects can an ASA support?

Hi,

In general the ASA does not have any limit to the number of ACL's limit. You can configure as many ACL's based on the available memory on the device. Whenever you apply an object-group, the ASA would internally expand those ACL's into multiple ACE's, so the expanded ACL is the original count. It depends on the platform and the memory installed. On some higher platforms like it might go higher than 2 million.

If you want to check the number of ACE's in your config, try:

show access-list | in elements

Hope this helps.

Thanks,

Varun

Thanks, Varun Rao Security Team, Cisco TAC