Link to home
Start Free TrialLog in
Avatar of Barnardos_2LS
Barnardos_2LS

asked on

Cisco ACL Processing Time

Hi,

Is their any evidence to suggest that the longer a Cisco ACL is, the greater the time from packet source to destination? Also, is their any evidence to suggest that the location of an ACL entry within the ACL also determines this time? Any links to evidence would be fantastic.

Mike
Avatar of pjtemplin
pjtemplin

There's tons of evidence and recommendations that you optimize your ACLs to put the most-hit clauses as close to the top as your policy will allow.  Long ACLs don't necessarily mean more latency or CPU utilization, but long ACLs where packets match very far down in the ACL (i.e. a final permit ip any any after 2000 lines) do mean more latency and CPU utilization.

On high-end routers, Cisco offers "turbo ACLs" which do not increase CPU load or latency based on ACL length.  That alone is evidence that ACL length (with respect to where in the ACL most packets match) matters.
Avatar of Barnardos_2LS

ASKER

Have you any links for these recommendations?

Mike
ASKER CERTIFIED SOLUTION
Avatar of pjtemplin
pjtemplin

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial