Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 939
  • Last Modified:

ACL's in Cisco 5520 Firewall

Hi

We have nearly 58K ACL lines in our ASA i want to remove unnecessary all ACL's from firewall is there any best way to monitor these ACLs and remove....??

what is the limit of ACL's in ASA 5520 (ver 8.2)

Thanks in advance  
0
amitabhg
Asked:
amitabhg
  • 2
  • 2
3 Solutions
 
fgasimzadeCommented:
You can check on hit counters to see if any of the lines are inactive.

I dont think there is a limit for access-lists lines, but you can also check CPU, since access-lists are CPU intensive
0
 
Ernie BeekExpertCommented:
There is no hard limit to the number of ACL's or ACE's in an ASA. It depends on the amount of memory to hold them and the CPU capacity to process them. If these are used to the max the firewall might start to get issues like dropping packets.

So you would like to monitor the rules to see how often they get hit? With show access-list you get to see the hitcount per ACE.
0
 
amitabhgAuthor Commented:
apart from seeing hit count is there any other way to monitor ACL's.
0
 
Ernie BeekExpertCommented:
Well, in the newer ASDMs versions you can also see the hitcount. I'm stall assuming that is what you want to monitor.
0
 
amitabhgAuthor Commented:
TanQ erniebeek.
0

Featured Post

Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

  • 2
  • 2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now