Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

Cisco ACL Processing Time

Posted on 2006-11-01
3
Medium Priority
?
505 Views
Last Modified: 2012-06-27
Hi,

Is their any evidence to suggest that the longer a Cisco ACL is, the greater the time from packet source to destination? Also, is their any evidence to suggest that the location of an ACL entry within the ACL also determines this time? Any links to evidence would be fantastic.

Mike
0
Comment
Question by:Barnardos_2LS
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
3 Comments
 
LVL 12

Expert Comment

by:pjtemplin
ID: 17852241
There's tons of evidence and recommendations that you optimize your ACLs to put the most-hit clauses as close to the top as your policy will allow.  Long ACLs don't necessarily mean more latency or CPU utilization, but long ACLs where packets match very far down in the ACL (i.e. a final permit ip any any after 2000 lines) do mean more latency and CPU utilization.

On high-end routers, Cisco offers "turbo ACLs" which do not increase CPU load or latency based on ACL length.  That alone is evidence that ACL length (with respect to where in the ACL most packets match) matters.
0
 
LVL 1

Author Comment

by:Barnardos_2LS
ID: 17856471
Have you any links for these recommendations?

Mike
0
 
LVL 12

Accepted Solution

by:
pjtemplin earned 1000 total points
ID: 17857566
0

Featured Post

On Demand Webinar: Networking for the Cloud Era

Did you know SD-WANs can improve network connectivity? Check out this webinar to learn how an SD-WAN simplified, one-click tool can help you migrate and manage data in the cloud.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I have seen some questions on problems with SSH/telnet access to Cisco routers that may occur despite the fact that from a PC connected to your LAN, Internet connectivity is in place and users can access Internet sites without any issues.  There are…
Problem Description:   Couple of months ago we upgraded the ADSL line at our branch office from Home to Business line. The purpose of transforming the service to have static public IP’s. We were in need for public IP’s to publish our web resour…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

722 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question