
4-20
Catalyst 6500 Series Switch and Cisco 7600 Series Router Firewall Services Module Configuration Guide using ASDM
OL-20748-01
Chapter 4 Configuring Security Contexts
Managing Memory for Rules
Est Data 96 96 96
AAA 1345 1345 2690
Console 384 384 768
-----------+---------+----------+---------
Total 19219 19219
Partition Limit - Configured Limit = Available to allocate
19219 - 19219 = 0
Note
If you increase the size of a partition but have not yet reloaded, the maximum number of rules
remains at the old smaller size. You have to reload to see the increased limits. If you decrease
the size of a partition but have not yet reloaded, the new smaller number of rules is reflected right
away.
Step 2
To view the number of rules currently being used so you can plan your reallocation, enter the following
command:
hostname(config)#
show np 3 acl count
partition_number
Where
partition_number
is between 0 and 11 by default. If you changed the number of partitions, the
partition numbering starts with 0. So if you have 10 partitions, the partition numbers are 0 through 9.
For example, the following is sample output from the
show np 3 acl count
command, and shows the
number of inspections (Fixup Rule) close to the maximum of 9216. You might choose to reallocate some
access list rules (ACL Rule) to inspections.
hostname(config)#
show np 3 acl count 0
-------------- CLS Rule Current Counts --------------
CLS Filter Rule Count : 0
CLS Fixup Rule Count :
9001
CLS Est Ctl Rule Count : 4
CLS AAA Rule Count : 15
CLS Est Data Rule Count : 4
CLS Console Rule Count : 16
CLS Policy NAT Rule Count : 0
CLS ACL Rule Count :
30500
CLS ACL Uncommitted Add : 0
CLS ACL Uncommitted Del : 0
...
Note
The
established
command creates two types of rules, control and data. Both of these types are
shown in the display, but you allocate both rules by setting the number of
established
commands; you do not set each rule separately.
Step 3
To identify the partition you want to customize, enter the following command in the system execution
space:
hostname(config)#
resource partition
number
Where
number
is between 0 and 11 by default. If you changed the number of partitions, the partition
numbering starts with 0. So if you have 10 partitions, the partition numbers are 0 through 9.
Step 4
To reallocate rules between features, enter the following command. If you increase the value for one
feature, then you must decrease the value by the same amount for one or more features so the total
number of rules does not exceed the system limit. See
Step 1
to use the
show resource rule
command
for the total number of rules allowed.
Содержание 6500 - Catalyst Series 10 Gigabit EN Interface Module Expansion
Страница 35: ...P A R T 1 Getting Started and General Information ...
Страница 36: ......
Страница 297: ...P A R T 2 Configuring the Security Policy ...
Страница 298: ......
Страница 521: ...P A R T 3 System Administration ...
Страница 522: ......
Страница 613: ...P A R T 4 Reference ...
Страница 614: ......