Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements
Step-by-Step Configuration and Troubleshooting Best Practices for the NGFW, NGIPS and AMP Technologies A Visual Guide to the Cisco Firepower Threat Defense (FTD)
Community Member

Firewall Switch Module 'admin' context is full

Hi i have been getting this message on my FWSM and was wondering how i go about resolving this.

Cheers

Kev

5 REPLIES
Community Member

Re: Firewall Switch Module 'admin' context is full

Hi

How many interfaces are allocated on the admin context?

The maximum amount of interface on one context is 256

Best regards Stefan (Sweden)

Community Member

Re: Firewall Switch Module 'admin' context is full

Hi,

This happens when i try and add a new ACL. Yet it says it has used only 75% anyone come accross this.

Regards

Kev

Re: Firewall Switch Module 'admin' context is full

Please can you post the error message.

Usually the message that you talking about is just indicating how much of the maximum ressources you have allready used. In your case you still have 25% of the maximum possible ACLs free of 75% of it used.

Do you use single or multiple context mode.

If you are in multi context mode then type the following command and post the result :

enable

changeto context system

show resource acl-partition

http://www.cisco.com/univercd/cc/td/doc/product/lan/cat6000/mod_icn/fwsm/fwsm_2_3/fwsm_ref/s.htm#wp2077431

Usually you have totaly limit, for the whole FWSM balde, of 150k ACLs.

Even if you split it to 12 (default) patitions then you have quit a lot of ACL.

150k / 12 = 12,5k ACLs. of each partitions and all firewalls in that partition.

Note: Remove confidential informations.

sincerely

Patrick

Community Member

Re: Firewall Switch Module 'admin' context is full

The Software Version is FWSM Firewall Version 2.3(1)7

FWSM Device Manager Version 4.1(2)

The Error message is ERROR: Unable to add, access-list config limit reached.

I suspect this is a book in the software version on the FWSM.

Cheers

Kev

Community Member

Re: Firewall Switch Module 'admin' context is full

Output from command:

FWSM# show resource acl-partition

Total number of configured partitions = 12

Partition #0

Mode : non-exclusive

List of Contexts : admin

Number of contexts : 1(RefCount:1)

Number of rules : 9569(Max:12248)

Partition #1

Mode : non-exclusive

List of Contexts : omnipay

Number of contexts : 1(RefCount:1)

Number of rules : 6427(Max:12248)

Partition #2

Mode : non-exclusive

List of Contexts : wups

Number of contexts : 1(RefCount:1)

Number of rules : 1523(Max:12248)

Partition #3

Mode : non-exclusive

List of Contexts : schemes

Number of contexts : 1(RefCount:1)

Number of rules : 270(Max:12248)

Partition #4

Mode : non-exclusive

List of Contexts : extranet

Number of contexts : 1(RefCount:1)

Number of rules : 408(Max:12248)

Partition #5

Mode : non-exclusive

List of Contexts : wucom

Number of contexts : 1(RefCount:1)

Number of rules : 759(Max:12248)

Partition #6

Mode : non-exclusive

List of Contexts : none

Number of contexts : 0(RefCount:0)

Number of rules : 0(Max:12248)

Partition #7

Mode : non-exclusive

List of Contexts : none

Number of contexts : 0(RefCount:0)

Number of rules : 0(Max:12248)

Partition #8

Mode : non-exclusive

List of Contexts : none

Number of contexts : 0(RefCount:0)

Number of rules : 0(Max:12248)

Partition #9

Mode : non-exclusive

List of Contexts : none

Number of contexts : 0(RefCount:0)

Number of rules : 0(Max:12248)

Partition #10

Mode : non-exclusive

List of Contexts : none

Number of contexts : 0(RefCount:0)

Number of rules : 0(Max:12248)

Partition #11

Mode : non-exclusive

List of Contexts : none

Number of contexts : 0(RefCount:0)

Number of rules : 0(Max:12248)

FWSM#

181
Views
0
Helpful
5
Replies
CreatePlease to create content