I have a Cisco 3660 on site with DS3 connection, and over the last two months we've been having conn

I have a Cisco 3660 on site with DS3 connection. Over the last two months we've been having connectivity issues: outside browsing slows down to crawl, clients can't ftp to us, etc. I've traced the problem down to ACLs on inbound interface. Our router also functions as a firewall, which brings me to my question: what are the limits that IOS firewall on 3660 can handle? (If I take off access lists, connectivity is perfect, but keeping ACLs off is not an option, so I'd like to know if I can tune them) Thank you very much.

    Requires Free Membership to View

You can and need to tweak the ACLs. Router looks at the ACLs in the order they are written. So it takes more processing power and time depending upon the number of ACL on the router. SO it would be better idea to combine ACL, if possible. Use most specific in the start and least specific in the last. End with deny any any. Also see if you can add some more memory to the router.

This was first published in September 2003

Join the conversationComment

Share
Comments

    Results

    Contribute to the conversation

    All fields are required. Comments will appear at the bottom of the article.