05-25-2006 11:46 AM - edited 02-20-2020 09:37 PM
Hi, I have a PIX525 with 6.3(4) with some large ACL's. I'd like to use the 'access-list compiled' command, but will this cause any disruption to traffic running through my production firewall?
05-25-2006 12:43 PM
Hi David,
The 'access-list compiled' (also known as turbo access-list) is meant to speed-up (improve) verification of passing traffic against huge ACL entries. It will not affect your firewall operation. Firewall read ACL entries based on 'top-down' mode (read from the 1st ACL down to the last statement).
You can apply it to individual ACL name or all ACLs.
Hope this helps!
Rgds,
AK
05-25-2006 07:13 PM
Use TurboACL only on PIX Firewall platforms that have 16 MB or more of Flash memory. Consequently, TurboACL is not supported on the PIX 501 because it has 8 MB of Flash memory.
If TurboACL is configured, some access control list or access control list group modifications can trigger regeneration of the TurboACL internal configuration. Depending on the extent of TurboACL configuration(s), this could noticeably consume CPU resources. Consequently, we recommend modifying turbo-complied access lists during non-peak system usage hours.
Rgds,
AK
05-25-2006 10:35 PM
Thanks AK for your answer. I'm really interested in knowing if there will be any disruption in traffic flow as a result of applying the 'access-list compiled'command for the first time.
05-26-2006 01:25 AM
Based on my own experienced, I do not see any immediate impact, e.g access suddenly become slow, session get disconnected/dropped and so on.
The firewalls (x2) had closed to 3000 lines of ACLs. I purposely applied the 'access-list compiled' on the 1st box during office hour and with many users/sessions, but so far, no hiccup.
I am not sure about your environment. Maybe it's better to do it after office hour, midnight or weekend to minimize interruption, plus plenty of time to do troubleshooting.
When you apply access-list compiled, Firewall will do some kind of indexing to the ACLs. It will not hold/prevent the ACL's to do traffic filtering processes.
Rgds,
AK
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide