Reallocating Rules Between Features - Cisco 7604 Configuration Manual

Catalyst 6500 series switch and cisco 7600 series router firewall services module configuration guide using the cli
Hide thumbs Also See for 7604:
Table of Contents

Advertisement

Rule Limits
Filter
Fixup
Est Ctl
Est Data
AAA
Console
-----------+---------+----------+---------
Total
Partition Limit - Configured Limit = Available to allocate

Reallocating Rules Between Features

You can reallocate rules from one feature to another feature.
In multiple context mode, you can also set the rule allocation per partition, which overrides the global
Note
setting in this section. See the
section on page
Guidelines
Failure to follow these guidelines might result in dropped access list configuration as well as other
Caution
anomalies, including ACL tree corruption.
Detailed Steps
To reallocate rules, perform the following steps:
Step 1
To view the total number of rules available, the default values, current rule allocation, and the absolute
maximum number of rules you can allocate per feature, enter the following command:
hostname(config)# show resource rule
For multiple context mode, enter this command in the system execution space. It shows the number of
rules per partition. See the
partitions.
For example, the following is sample output from the show resource rule command, and shows the
maximum rules as 124923 in single mode (this is an example only, and might differ from the actual
number of rules for your system):
hostname(config)# show resource rule
Catalyst 6500 Series Switch and Cisco 7600 Series Router Firewall Services Module Configuration Guide using ASDM
A-8
576
1537
1537
96
96
1345
1345
384
19219
19219
19219
-
19219
4-19.
The target partition and rule allocation settings must be carefully calculated, planned, and preferably
tested in a non-production environment prior to making the change to ensure that all existing
contexts and rules can be accommodated.
When failover is used, both FWSMs need to be reloaded at the same time after making partition
changes. Reloading both FWSMs causes an outage with no possibility for a zero-downtime reload.
At no time should two FWSMs with a mismatched number of partitions or rule limits synchronize
over failover.
"About Memory Partitions" section on page 4-12
576
1152
3074
96
96
96
96
2690
384
768
=
0
"Reallocating Rules Between Features for a Specific Memory Partition"
Appendix A
Specifications
for more information about
OL-20748-01

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

7609-s76137606-sCatalyst 6500 series7600 series

Table of Contents