Hi, Is a packet filter still considered relevant discussion here? :)
I'm being asked to convert our Cisco IOS ACLs to VACLs to decrease the performance impact on our routers. However, reading the implementation documentation (instead of the sales literature) makes me question whether there will be any advantage. Environment: 6513 with Sup1A/PFC/MSFC with long lists of layer four ACLs. Various documents say that both ACL and VACL processing is done in hardware with the MSFC unless logging is involved. If they're both done in hardware, where is the performance improvement? Is it different hardware or was the performance improvement only for the older Sup1 engine without the MSFC card which processed IOS ACLs in software? Thanks for any insight. -- Gary Flynn Security Engineer - Technical Services James Madison University Please R.U.N.S.A.F.E. http://www.jmu.edu/computing/runsafe _______________________________________________ Firewalls mailing list [EMAIL PROTECTED] For Account Management (unsubscribe, get/change password, etc) Please go to: http://lists.gnac.net/mailman/listinfo/firewalls
