[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: ACLs



"Smith, Donald" <Donald.Smith@qwest.com> writes:

> How about 1000 line acl/ less then 10 millisecond impact?? or something like
> that.

ACL costs are not proportional to line count.  One device can filter
at wirespeed from, say, 30,000 lines of ACLs, to less than 1,000,
depending on the ACL enties.  Requiring a minimum of "mutually
independent ACL entries" (which do not depend on processing order)
might be more feasible.

However, where should we draw the boundary?  IMHO, 100 is far too low
for practical purposes, but why 500, 1000?

In the end, it's also a choice you have as a purchaser.  Even for
GSRs, you can buy a truly ACL-capable OC48 interface right now, but it
has got a certain price tag.  If you don't want to filter in the core,
why should pay the additional price?

To me, this whole ACL issue starts to look more and more like
something which requires vendor documentation, but not necessarily
specific implementations.