le 21-10-2024 08:38 AM
I have a catalyst 9500 and I recently cleaned up the ACLs (ip access-list extended applied to interface). I just removed some entries which were useless. Then some unchanged rules did not applied anymore. I don't have any idea of what happen.
The thing is that if I recreate these rules above (i.e. upper in the list of rules) they are taken into account.
Could it be due to a maximum number of entries reached and if so why was it working with more entries before I cleaned up the list?
Any help would be appreciate.
le 21-10-2024 09:37 AM
what was the error, what IOS XE code running.
check the limit here :
le 21-10-2024 09:43 AM
Can you provide the original ACL list and then the list after the entries were removed? (Along with an example of something that 'did no apply anymore' after the removal)? It's hard to determine the underlying issue without more concrete information.
As for ACL rule length, the practical ACL limit is not the number of entries but rather the CPU and memory on the system. I know that ASAs don't have an actual limit on the number of entries you can have, and if there is one on the 9500 it would be in the thousands for an extended ACL.(Standard ACLs do have a limit, but I don't remember what it is off the top of my head.)
Maren
Découvrez et enregistrez vos notes préférées. Revenez pour trouver les réponses d'experts, des guides étape par étape, des sujets récents et bien plus encore.
Êtes-vous nouveau ici? Commencez par ces conseils. Comment utiliser la communauté Guide pour les nouveaux membres
Parcourez les liens directs de la Communauté et profitez de contenus personnalisés en français