
4-19
Catalyst 6500 Series Switch and Cisco 7600 Series Router Firewall Services Module Configuration Guide using ASDM
OL-20748-01
Chapter 4 Configuring Security Contexts
Managing Memory for Rules
-----------+---------+----------+-----------
0
49970
49970
40000
1
49969
49969
40000
2
49969
49969
56616
3
49969
49969
56615
backup tree
49970
49970
56616
-----------+---------+----------+-----------
Total 249847 249847
249847
Total Partition size - Configured size = Available to allocate
249847 -
249847 =
0
hostname(config-partition)#
reload
Reallocating Rules Between Features for a Specific Memory Partition
To set the rule allocation globally for all partitions, see the
“Reallocating Rules Between Features”
section on page A-8
. Setting the rule allocation for a specific partition overrides the global setting.
Guidelines
Caution
Failure to follow these guidelines might result in dropped access list configuration as well as other
anomalies, including ACL tree corruption.
•
The target partition and rule allocation settings must be carefully calculated, planned, and preferably
tested in a non-production environment prior to making the change to ensure that all existing
contexts and rules can be accommodated.
•
When failover is used, both FWSMs need to be reloaded at the same time after making partition
changes. Reloading both FWSMs causes an outage with no possibility for a zero-downtime reload.
At no time should two FWSMs with a mismatched number of partitions or rule limits synchronize
over failover.
Detailed Steps
To reallocate rules for a given partition, perform the following steps:
Step 1
To view the total number of rules available per partition, the default values, current rule allocation, and
the absolute maximum number of rules you can allocate per feature, enter the following command:
hostname(config)#
show resource rule partition
[
number
]
For example, the following display shows the maximum rules as 19219 for partition 0 (this is an example
only, and might differ from the actual number of rules for your system):
hostname(config)#
show resource rule partition 0
Default Configured Absolute
CLS Rule Limit Limit Max
-----------+---------+----------+---------
Policy NAT 384 384 833
ACL 14801 14801 14801
Filter 576 576 1152
Fixup 1537 1537 3074
Est Ctl 96 96 96
Содержание 6500 - Catalyst Series 10 Gigabit EN Interface Module Expansion
Страница 35: ...P A R T 1 Getting Started and General Information ...
Страница 36: ......
Страница 297: ...P A R T 2 Configuring the Security Policy ...
Страница 298: ......
Страница 521: ...P A R T 3 System Administration ...
Страница 522: ......
Страница 613: ...P A R T 4 Reference ...
Страница 614: ......