
4-12
Catalyst 6500 Series Switch and Cisco 7600 Series Router Firewall Services Module Configuration Guide using ASDM
OL-20748-01
Chapter 4 Configuring Security Contexts
Managing Memory for Rules
About Memory Partitions
In multiple context mode, the FWSM partitions the memory allocated to rule configuration, and assigns
each context to a partition. By default, a context belongs to one of 12 partitions that offers a maximum
number rules, including ACEs, AAA rules, and others. See the
“Default Rule Allocation”
section for a
list of rule limits.
The FWSM assigns contexts to the partitions in the order they are loaded at startup. For example, if you
have 12 contexts and the maximum number of rules is 14,103, each context is assigned to its own
partition, and can use 14,103 rules. If you add one more context, then context number 1 and the new
context number 13 are both assigned to partition 1, and can use 14,103 rules divided between them; the
other 11 contexts continue to use 14,103 rules each. If you delete contexts, the partition membership
does not shift, so you might have some unequal distribution until you reboot, at which time the contexts
are evenly distributed.
Note
Rules are used up on a first come, first served basis, so one context might use more rules than another
context.
You can manage memory partitions by manually assigning a context to a partition (see the
“Configuring
a Security Context” section on page 4-27
); reducing the number of partitions to better match the number
of contexts you have (see the
“Setting the Number of Memory Partitions” section on page 4-13
);
changing the size of a partition (see the
“Changing the Memory Partition Size” section on page 4-14
);
and reallocating rules between features (see the
“Reallocating Rules Between Features for a Specific
Memory Partition” section on page 4-19
).
Default Rule Allocation
Table 4-1
lists the default number of rules for each feature type in multiple context mode, for the default
12 memory partitions.
Note
Some access lists use more memory than others. Depending on the type of access list, the actual limit
the system can support will be less than the maximum. See the
“Maximum Number of ACEs” section on
page 13-6
for more information about ACEs and memory usage.
Table 4-1
Default Rule Allocation
Specification
Maximum per Partition (with 12
1
Partitions)
1.
Use the
show resource rule
command to view the default values for partitions other than 12.
AAA Rules
1345
ACEs
14,801
established
commands
2
96
Filter Rules
576
ICMP, Telnet, SSH, and HTTP Rules
384
Policy NAT ACEs
3
384
Inspect Rules
1537
Total Rules
19,219
Summary of Contents for 6500 - Catalyst Series 10 Gigabit EN Interface Module Expansion
Page 35: ...P A R T 1 Getting Started and General Information ...
Page 36: ......
Page 297: ...P A R T 2 Configuring the Security Policy ...
Page 298: ......
Page 521: ...P A R T 3 System Administration ...
Page 522: ......
Page 613: ...P A R T 4 Reference ...
Page 614: ......