cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2674
Views
2
Helpful
2
Replies

guidance of the max lines for DACLs in ISE

mpeeters
Cisco Employee
Cisco Employee

Partner is looking for guidance on the max # of lines for port based DACLs.

Are there hard numbers for the max # of lines in ISE itself ?

Do the switches have per port max or are the there shared numbers across the ports themselves ?

Is there any documentation that outlines the numbers per switch ?

Thx

1 Accepted Solution

Accepted Solutions

mpeeters
Cisco Employee
Cisco Employee

found this post that appears to address the question


https://communities.cisco.com/thread/80527

View solution in original post

2 Replies 2

mpeeters
Cisco Employee
Cisco Employee

found this post that appears to address the question


https://communities.cisco.com/thread/80527

B. BELHADJ
Level 4
Level 4

Hello

Unfortunately, there is no official documentation about that. But in this doc ACS vs ISE Comparison the maximum ACL in ISE 2.2 is 8000 (I think the combination between the ACLs and ACEs).

For the switches you have some limitations because it depends on the performance and the TCAM (Ternary Content Addressable Memory). For example, the Nexus 5000 supports until 1024 for the VLAN ACL for the whole switch and 128 for the Port ACL per Physical Interface.

I hope that can help.

Best regards

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: