11-20-2013 09:55 AM
Hello,
We run an access service here using the ASA 5545-X and AnyConnect clients. We make extensive use of Dynamic Access Policies to build per-user firewall rules based on membership in authorization groups. As the number of users grows, the total number of ACL instances or objects (not sure what to call them) could get quite large. Is there an upper limit on these? Is there an upper limit on the number of ACL 'templates' or 'classes' that can be defined?
Thanks,
Mike Wiseman
Information Security
University of Toronto
11-20-2013 11:05 AM
Hi,
To my understanding the the only limitation for ACLs in the memory on the ASA. And to my understanding the situation with the new ASA5500-X Series with regards to memory is a lot better than the older models.
This is from a Cisco Live! presentation (click to enlarge)
You can visit and register at https://www.ciscolive365.com/ and you can gain access to a lot of great presentations of different subjects. In some cases you can watch the whole presentation video from the Cisco Live! session.
Hope this helps
- Jouni
11-21-2013 11:12 AM
Thanks Jouni - good to know.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide