Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

Number of rules within the PIX

Does anyone know if Cisco has a recommendation for the number of rules/access list lines per firewall? I know within Check Point, there is a recommendation for no more than 50 rules per firewall within the Security Policy Rule Base. Looking for an answer for an audit question.

2 REPLIES
New Member

Re: Number of rules within the PIX

with pix 6.2 and complied access lists, multi-thousand line lists were tested and worked fine. the real limit is in available memory to compile the list, you need minimum 2M free to compile.

New Member

Re: Number of rules within the PIX

I'm running 900+ on PIX525 with no problems at all (other than managing the cotton pickin things ;-0 ).

Cpu is nothing 2-5% tops with approximtely 2000+ connections.

93
Views
8
Helpful
2
Replies