cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
236
Views
0
Helpful
2
Replies

PIX Access Lists

jeff.carr
Level 1
Level 1

I finally got around to changing my conduits to access list entries. Should I adjust the order of the access list entries, keeping the busy entries first in line? My assumption is that the access list group is queried in order, similar to an IOS driven device. Thanks for the input.

2 Replies 2

Patrick Iseli
Level 7
Level 7

Yes you should put the more busy ones in the beginning.

By the way there are two interesting features for access-list.

1.) Turbo access-list

TurboACL is a feature introduced with PIX Firewall version 6.2 that improves the average search time for access control lists containing a large number of entries. The TurboACL feature causes the PIX Firewall to compile tables for ACLs and this improves searching of long ACLs.

[no] access-list compiled

[no] access-list compiled

See: http://www.cisco.com/en/US/products/sw/secursw/ps2120/products_configuration_guide_chapter09186a00800eb721.html#wp1034390

2.) You can add access-list with a statement, see eample:

[no] access-list [line ] deny|permit ...

sincerely

Patrick

Excellent.

Thanks for the response, and for the info on 'TurboACL' and 'add ACL with line num'. Will come in handy.

Jeff

Review Cisco Networking for a $25 gift card