cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
756
Views
5
Helpful
4
Replies

Adding entire China public IP addresses into IOS

desmond.liew
Level 1
Level 1

Hi All,

Does anyone know if there will be issues when creating an extended ACL of over 4000 lines?

I have two sites; China and Hong Kong. Some Internet sites are unreachable in China and are others reachable in Hong Kong. So, using DMVPN, I'll route non-China traffic via Hong Kong and the rest out via its local Internet. Here are my questions:

1. Instead of creating a 4000lines of acl, is there a dynamic way of doing this?

2. If there isn't a way, will this impact router performance? The router I am using is a C891.

Sent from Cisco Technical Support iPhone App

1 Accepted Solution

Accepted Solutions

paolo bevilacqua
Hall of Fame
Hall of Fame

Can't you re-route only the troubled destinations? These would much less, there is probably a list maintaned somewhere.

Anyway, 4000 lines ACL  is doable, but I would recommedn against. You can enable access-list compiled to reduce performance hit.

View solution in original post

4 Replies 4

paolo bevilacqua
Hall of Fame
Hall of Fame

Can't you re-route only the troubled destinations? These would much less, there is probably a list maintaned somewhere.

Anyway, 4000 lines ACL  is doable, but I would recommedn against. You can enable access-list compiled to reduce performance hit.

I did this on my ASA 5510, It can be done but not dynamically (ASA or router can not import it from some other place), you have to create the IP list line by line in a text editor then past it to your device.

desmond.liew
Level 1
Level 1

Hi Paolo and Chris,

Thanks for the advice. I googled up on how to do access-list compiled but the sorry thing is that it is available on the 7200 series, 7500 series or higher models. I tried on my C891 running v12.4 but the command doesn't exist. I have a C1911 running v15.0 but that command doesn't exist. So that's out the window for me.

I also just implemented the 4000 lines into my router last week and so far so good. I have a NMS to monitor the load and it looks okay (< 15% cpu). Or maybe these series of routers are beefy enough to handle this.

Thanks for your response, guys.

Sent from Cisco Technical Support iPhone App

Glad to be of help, please remember to rate useful posts clicking on the stars below.

Review Cisco Networking products for a $25 gift card