Carl,


I think it would generally depend on the platform, processor & amount of memory.


Best practise is to create groups for specific rules, containing subnets, hosts, services, protocols etc on a per rule basis.


This aids better troubleshooting for a rule base perspective and logs, with the ACL's.


HTH.

Actions

This Discussion