cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
829
Views
0
Helpful
2
Replies

Dynamic Access Policies - limit in ASA 9.4 ?

Patrick Tran
Level 1
Level 1

Hi,

Is there a maximum number of DAP supported by ASA 55XX 9.4 ?

Cisco recommanded a maximum of 100 in 9.1. Is this still true in 9.4?

Thanks,

Patrick

1 Accepted Solution

Accepted Solutions

rvarelac
Level 7
Level 7

Hi Patrick , 

 

There is not virtual limit for the DAP policies you can create on the ASA, this will depend more of the hardware you're using rather than the code the ASA is running. However there is a limit for the attributes inside each DAP.

Currently a maximum of 5000 values/instances can be processed per  attribute in each DAP.
A syslog is generated when this limit is passed:
%ASA-3-109035: Exceeded maximum number (5000) of DAP attribute instances for 
user = <username>


Hope it helps

-Randy-

View solution in original post

2 Replies 2

rvarelac
Level 7
Level 7

Hi Patrick , 

 

There is not virtual limit for the DAP policies you can create on the ASA, this will depend more of the hardware you're using rather than the code the ASA is running. However there is a limit for the attributes inside each DAP.

Currently a maximum of 5000 values/instances can be processed per  attribute in each DAP.
A syslog is generated when this limit is passed:
%ASA-3-109035: Exceeded maximum number (5000) of DAP attribute instances for 
user = <username>


Hope it helps

-Randy-

Thanks for your quick answer, Randy !!

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: