Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
perkt11
Participant

Check Point ACL Limits

Good morning,

Cisco ASAs have limits on ACL/ACE entries. I cannot find any literature that suggest such limits on Check Point Firewalls.

I am particularly interested in the 6000 and 7000 family lines.

Does anyone know if Check Point FWs have ACL/ACE entries?

Thanks!

Tom

0 Kudos
6 Replies
_Val_
Admin
Admin

Check Point FWs do not have a notion of ACL. We operate with policy rules and objects. 

Although there is an impact of the number of rules and objects in use to the GW performance, there is no hard limit for either. 

To moderate the situation, you can use various tech solutions and procedures, look into sk98348 for more details.

0 Kudos
perkt11
Participant

Thanks Val!

_Val_
Admin
Admin

No problem. Let me know if you need any further assistance. 

0 Kudos
the_rock
Legend
Legend

Put it this way...yes, @_Val_ is correct, there is no "official" limit, BUT...I can tell you from my experience, any environment I had seen with more than say 1000 rules, it will take a bit of time to push policy. Yes, with R81, there is accelerate policy push so that helps for sure. I recall in old days of CP, I always use to hear number of 10000 rules as a limit, but again, it was never officially stated anywhere.

0 Kudos
perkt11
Participant

Thanks Rock for the follow up.

0 Kudos
the_rock
Legend
Legend

No problem at all!

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events