cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements

1253
Views
5
Helpful
2
Replies
Nikhil5
Beginner

Object Group search feature in FTD 2110 version 6.6.1

Hello,

We have just upgraded FTD 2110 firewall to firmware version 6.6.1. Since the AC element count is 800k, FMC shows a warning message "the number of access list elements generated for the access control policy exceeds the limit for this platform", suggesting to enable "Object Group Search". I have checked Cisco's documentation but could not get proper information, could anyone of you help me?

 

1. Is it recommended to enable "object group search"?

2. Does it increase the CPU usage of the firewall? The below document says it doesn't affect CPU usage.

 

1 ACCEPTED SOLUTION

Accepted Solutions
Chakshu Piplani
Cisco Employee

Hi Nikhil,

 

Kindly go through:

https://www.cisco.com/c/en/us/td/docs/security/firepower/660/configuration/guide/fpmc-config-guide-v66/device_management_basics.html#Cisco_Task_in_List_GUI.dita_da6fee26-4eb9-420f-b40b-d623b170e910

 

"Enabling object group search reduces memory requirements for access control policies that include network objects. However, it is important to note that object group search might also decrease rule lookup performance and thus increase CPU utilization. You should balance the CPU impact against the reduced memory requirements for your specific access control policy. In most cases, enabling object group search provides a net operational improvement. "

 

Also:

https://www.linkedin.com/pulse/object-group-search-underrated-new-feature-nikolaj-pabst-nielsen/?trk=related_artice_Object%20Group%20Search%20-%20The%20underrated%20%26amp%3Bamp%3Bquot%3Bnew%26amp%3Bamp%3Bquot%3B%E2%80%8B%20feature!_article-card_titl...

 

Regards,

Chakshu

View solution in original post

2 REPLIES 2
Marvin Rhoads
VIP Community Legend

It is definitely recommended in a case like yours. As noted, performance will be helped and no additional CPU usage should result.

Chakshu Piplani
Cisco Employee

Hi Nikhil,

 

Kindly go through:

https://www.cisco.com/c/en/us/td/docs/security/firepower/660/configuration/guide/fpmc-config-guide-v66/device_management_basics.html#Cisco_Task_in_List_GUI.dita_da6fee26-4eb9-420f-b40b-d623b170e910

 

"Enabling object group search reduces memory requirements for access control policies that include network objects. However, it is important to note that object group search might also decrease rule lookup performance and thus increase CPU utilization. You should balance the CPU impact against the reduced memory requirements for your specific access control policy. In most cases, enabling object group search provides a net operational improvement. "

 

Also:

https://www.linkedin.com/pulse/object-group-search-underrated-new-feature-nikolaj-pabst-nielsen/?trk=related_artice_Object%20Group%20Search%20-%20The%20underrated%20%26amp%3Bamp%3Bquot%3Bnew%26amp%3Bamp%3Bquot%3B%E2%80%8B%20feature!_article-card_titl...

 

Regards,

Chakshu

View solution in original post

Create
Recognize Your Peers
Polls
Which of these topics should we host an event in the Community?

Top Choice: ISE Demo (100%)

Content for Community-Ad