Reallocating Rules Between Features For A Specific Memory Partition - Cisco 7604 Configuration Manual

Catalyst 6500 series switch and cisco 7600 series router firewall services module configuration guide using the cli
Hide thumbs Also See for 7604:
Table of Contents

Advertisement

Chapter 4
Configuring Security Contexts
-----------+---------+----------+-----------
backup tree
-----------+---------+----------+-----------
Total
Total Partition size - Configured size = Available to allocate
hostname(config-partition)# reload

Reallocating Rules Between Features for a Specific Memory Partition

To set the rule allocation globally for all partitions, see the
section on page
Guidelines
Failure to follow these guidelines might result in dropped access list configuration as well as other
Caution
anomalies, including ACL tree corruption.
Detailed Steps
To reallocate rules for a given partition, perform the following steps:
To view the total number of rules available per partition, the default values, current rule allocation, and
Step 1
the absolute maximum number of rules you can allocate per feature, enter the following command:
hostname(config)# show resource rule partition [number]
For example, the following display shows the maximum rules as 19219 for partition 0 (this is an example
only, and might differ from the actual number of rules for your system):
hostname(config)# show resource rule partition 0
CLS Rule
-----------+---------+----------+---------
Policy NAT
ACL
Filter
Fixup
Est Ctl
Catalyst 6500 Series Switch and Cisco 7600 Series Router Firewall Services Module Configuration Guide using ASDM
OL-20748-01
0
49970
49970
1
49969
49969
2
49969
49969
3
49969
49969
49970
49970
249847
249847
249847 -
A-8. Setting the rule allocation for a specific partition overrides the global setting.
The target partition and rule allocation settings must be carefully calculated, planned, and preferably
tested in a non-production environment prior to making the change to ensure that all existing
contexts and rules can be accommodated.
When failover is used, both FWSMs need to be reloaded at the same time after making partition
changes. Reloading both FWSMs causes an outage with no possibility for a zero-downtime reload.
At no time should two FWSMs with a mismatched number of partitions or rule limits synchronize
over failover.
Default
Configured
Limit
Limit
384
14801
14801
576
1537
1537
96
40000
40000
56616
56615
56616
249847
249847 =
Absolute
Max
384
833
14801
576
1152
3074
96
96
Managing Memory for Rules
0
"Reallocating Rules Between Features"
4-19

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

7609-s76137606-sCatalyst 6500 series7600 series

Table of Contents