cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1295
Views
0
Helpful
1
Replies

access-list has port selectors may have performance impact

sstrohmayer
Level 1
Level 1

Can someone quantify this, I added a very large access-list (130 entries) to a tunnel a few days ago on an old pix and customer traffic was heavily impacted the pix setup:

"Version 5.1(2), Finesse Bios V3.3, Hardware: SE440BX2, 128 MB RAM, CPU Pentium II 349 MHz"

What kind of impact would this have, anyone any ideas?

1 Reply 1

nkhawaja
Cisco Employee
Cisco Employee

With older codes we didn't have the feature called "compile", without it, for a long access-list firewall has to match an incoming packet against all the entries in sequential manner unless it hits a match or unless a default action is applied.