ASA 5505 Sec Plus 9.0 OS
I want to create a country ACL that allows only US IP's through my firewall for certain ports. The problem is that the most up-to-date US IP list I can find contains 46000 lines! Even though some of these entries can be combined into larger blocks many of them can't because of just a few IP's (relatively) belonging to other countries. Even if I just use the /8 and /16 subnets that's still about 5800 network-object entries for the object-group.
Can I even have an object-group with 5800 entries? Would that slow down my ASA? Is there an easier way to do this?
The short answer is yes, but will you notice, maybe but I don't think it will hinder it too much. To go through all the lines and find the match will require some CPU headroom. I would add half of them and check the CPU. Then add the rest and see what happens. My guess, you should be fine.