cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2726
Views
0
Helpful
2
Replies

ACL optimization

ahmedraees
Level 1
Level 1

I have 14000 ACEs under one ACL. Actually I want to  block whole of the world except North America and Mexico. Any idea how to optimize this list . Any tool

2 Replies 2

Hi,

If you just want to permit some ranges and deny everything else, the recommendation is to specify what you want to permit and by default everything else will be denied.

If this is an ASA, you can use Object-Groups to group networks and in this way reduce dramatically the list.

Federico.

Hi,

If you are using FWSM then you can use ACL optimization future. It will analyse and will give the report of zero hit count ACLs.

You can remove those ACLs.

Else, you have to enable logging and you have to find the zero hit-count and remove those zero hit count ACLs

Regards

Karuppu

Review Cisco Networking products for a $25 gift card