Cisco PIX 525 Especificações Página 131

  • Descarregar
  • Adicionar aos meus manuais
  • Imprimir
  • Página
    / 466
  • Índice
  • MARCADORES
  • Avaliado. / 5. Com base em avaliações de clientes
Vista de página 130
3-19
Cisco PIX Firewall and VPN Configuration Guide
78-15033-01
Chapter 3 Controlling Network Access and Use
Using TurboACL
Note When you add or delete an element from a turbo-enabled ACL the internal data tables associated with
the ACL are regenerated, which produces an appreciable load on the PIX Firewall CPU.
The TurboACL feature requires significant amounts of memory and is most appropriate for high-end
PIX
Firewall models, such as the PIX 525 or PIX 535. The minimum memory required for TurboACL
is 2.1 MB and approximately 1 MB of memory is required for every 2000 ACL elements. The actual
amount of memory required depends not only on the number of ACL elements but also on the complexity
of the entries.
Note With PIX Firewall models having limited memory, such as the PIX 501, implementing the TurboACL
feature may cause problems, such as not being able to load Cisco PIX Device Manager (PDM). If
memory problems occur after enabling TurboACL, disable it using the no access-list compiled
command.
Globally Configuring TurboACL
The syntax for enabling TurboACL for the entire PIX Firewall is as follows:
access-list compiled
This configures TurboACL on all ACLs having 19 or more entries. This command causes the TurboACL
process to scan through all existing ACLs. During the scan, it marks and turbo-compiles any ACL which
has 19 or more access control entries (ACEs) and has not yet been turbo-compiled.
The command no access-list compiled, which is the default, causes the TurboACL process to scan
through all compiled ACLs and mark every one as non-turbo. It also deletes all existing TurboACL
structures.
When the PIX Firewall is running, the command access-list compiled marks every ACL to be
turbo-configured, and the command no access-list compiled marks every ACL as non-turbo.
Configuring Individual TurboACLs
The individual TurboACL command can be used to enable individual turbo configuration for individual
ACLs when TurboACL is not globally enabled. Also, after globally configuring TurboACL, you can
disable the turbo-compiled feature for individual ACLs by using the individual TurboACL command.
The syntax of this command is as follows.
access-list acl_name compiled
This command is used to individually enable or disable TurboACL on a specific ACL. The acl_name
must specify an existing ACL. This command will cause the TurboACL process to mark the ACL
specified by acl_name to be turbo-compiled if the ACL has 19 or more ACEs and has not yet been
turbo-compiled.
If you enter the no form of the command, the TurboACL process deletes the TurboACL structures
associated with the ACL and marks the ACL as non-turbo.
Vista de página 130
1 2 ... 126 127 128 129 130 131 132 133 134 135 136 ... 465 466

Comentários a estes Manuais

Sem comentários