Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

Firewall Performance

Folks,

How can I get the best performance to my Firewall?

I have a ASA with 8 interfaces into a single context and 1500 lines of ACL.

Is there any rule to improve more performance about ACL?

For example, what's the better option, do I need to use object-group or linear ACL?

Have Cisco any recomendations about ACL?

thanks a lot

2 REPLIES
Hall of Fame Super Blue

Re: Firewall Performance

danielnunes wrote:

Folks,

How can I get the best performance to my Firewall?

I have a ASA with 8 interfaces into a single context and 1500 lines of ACL.

Is there any rule to improve more performance about ACL?

For example, what's the better option, do I need to use object-group or linear ACL?

Have Cisco any recomendations about ACL?

thanks a lot

Daniel

Object-groups are really just a way to organise your access-lists in a more efficient way but they won't have a huge impact on performance. The recommendation for acls is to -

1) have more specific rules at the top and more general later

2) try and have the rules that are being hit the most near the top of the acl because as soon as a match is found in the acl processing of the acl stops. Obviously you must take into account 1) when doing this.

In addition it is quite common for a firewall rule base to grow very large due to new access being needed but often some of the older rules are no longer needed. It is worth checking on the hit count for the acls because you may find a certain amount of the rules are no longer being used.

Jon

Re: Firewall Performance

To add a little more info to what Jon is saying, if you have a group of single hosts that will need access to the say destination on a bunch of different ports, then it is good to keep your acl count lower by setting up an Object-group for the hosts and a Service-group for the ports and a single acl for it all.  This does help in keeping down the number of lines of acls you need.  It also helps to setup a naming convention for the object-groups that makes it easy to remember what the group is used for.  I personally have found using a combination of object-groups to keep the number of acls down to a minimum.

Thanks,

Kimberly

Thanks and Cheers! Kimberly Please remember to rate helpful posts.
412
Views
0
Helpful
2
Replies
CreatePlease login to create content