fadi4alpha wrote:
Is using the Object-Group will reduce the processing effort ?
and is there any documents for ACL design consedieriation ?
Thanks a lot in advance.
Using object-groups does not reduce the processing effort because the firewall still has to expand the object-group into it's individual line entries. It's more a way of organising the config from an admin perspective.
ACL design, not really documents but the key thing is to put the entries that are hit the most at the top as the acl entries are processed top down, one at a time.
Jon