10-14-2020 03:49 AM
Hello,
I have a N3K-C3064PQ-10GX and i have 2x 10g LACP uplink from my upstream and i have 2x 10G LACP downlink to my access switch, and i have 2x acl , one of them has been applied on UPLINK input and one of them has been applied to downlink input and every access list has around 30-50 lines for control packets, because i need to drop the specific traffic to some prefixes and both of them end line has permit IP any any , so i read 3064 datasheet and it shows its supporting 2k ingress and 1k egress acl, and i have around 15g bps and 4-5m pps on my network, so i want to make sure am i safe to continue using acl ? i do not need worry about cpu usages? because iread other questions and it seems i should check buffer instead of cpu, thanks,
Solved! Go to Solution.
10-14-2020 05:33 AM
Its not good to have so many ACL on nexus switches if you asked personally i prefer to have FW in place.
But its not effecting your environment - that is acceptable for business, yes go for it.
10-14-2020 05:33 AM
Its not good to have so many ACL on nexus switches if you asked personally i prefer to have FW in place.
But its not effecting your environment - that is acceptable for business, yes go for it.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide