ACL's in Cisco 5520 Firewall

Posted on 2011-09-02
Last Modified: 2013-12-07

We have nearly 58K ACL lines in our ASA i want to remove unnecessary all ACL's from firewall is there any best way to monitor these ACLs and remove....??

what is the limit of ACL's in ASA 5520 (ver 8.2)

Thanks in advance  
Question by:amitabhg
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
LVL 18

Accepted Solution

fgasimzade earned 167 total points
ID: 36472669
You can check on hit counters to see if any of the lines are inactive.

I dont think there is a limit for access-lists lines, but you can also check CPU, since access-lists are CPU intensive
LVL 35

Assisted Solution

by:Ernie Beek
Ernie Beek earned 333 total points
ID: 36472676
There is no hard limit to the number of ACL's or ACE's in an ASA. It depends on the amount of memory to hold them and the CPU capacity to process them. If these are used to the max the firewall might start to get issues like dropping packets.

So you would like to monitor the rules to see how often they get hit? With show access-list you get to see the hitcount per ACE.

Author Comment

ID: 36473679
apart from seeing hit count is there any other way to monitor ACL's.
LVL 35

Assisted Solution

by:Ernie Beek
Ernie Beek earned 333 total points
ID: 36473721
Well, in the newer ASDMs versions you can also see the hitcount. I'm stall assuming that is what you want to monitor.

Author Comment

ID: 36487619
TanQ erniebeek.

Featured Post

Create the perfect environment for any meeting

You might have a modern environment with all sorts of high-tech equipment, but what makes it worthwhile is how you seamlessly bring together the presentation with audio, video and lighting. The ATEN Control System provides integrated control and system automation.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I recently attended Cisco Live! in Las Vegas, a conference that boasted over 28,000 techies in attendance, and a week of hands-on learning hosted by a solid partner with which Concerto goes to market.  Every year, Cisco displays cutting-edge technol…
Many of the companies I’ve worked with have embraced cloud solutions due to their desire to “get out of the datacenter business.” The ability to achieve better security and availability, and the speed with which they are able to deploy, is far grea…
After creating this article (, I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor ( If you're looking for how to monitor bandwidth using netflow or packet s…

734 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question