11-29-2011 01:25 PM - edited 03-11-2019 02:57 PM
I was just curious if there are any performance benefits of using multiple network objects on multiple rules vs consolidating them into fewer rules by grouping them?
For example, I have about 10 lines of NAT exempt rules from the same source to multiple destinations. Is there anything to be gained if I consolidated those into a single rule using an object group for the multiple destinations aside from cleaning up the clutter in ASDM?
Thanks
11-29-2011 01:51 PM
Hello Tony,
Of course, it will be better because the processing that the ASA is going to use to determine witch rule to match would be decremented, also it would take less space on the configuration file (memory). those are some of the pros regarding creating groups for particular rules.
Sometimes a huge configuration file can increment the CPU usage,etc,etc. so it is better to keep it as small and organized as possible.
Please rate helpful posts.
Regards,
Julio
11-29-2011 01:53 PM
Well using object group is easy for sure no performance benifit but easy to manage things also less configuration is required . Consider it like if you need to same ACL -
Source is A
Destination B C D
Total 4 ACL right instead of doing that you can create two object groups Object A and B and you can add networks over there . When you will look at actual lines added would be 4.
so nothing but it makes job easy.
Thanks
Ajay
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide