Thursday, August 8, 2019

Cisco ASA | Access-List Logging | Does it punt to the CPU?

Hi,

I am aware on a Cisco router if you use the keyword "log" at the end of an access list, any traffic passing through that access list is punted up to the CPU for processing which understandably can cause throughput issues if you're pushing enough traffic.

Is this the case with Cisco ASA's too?

I want to log my access list hits and export them to a syslog server, but I am also conscious if this behaves the same way as a Cisco router would this could be an issue.

Thank You



No comments:

Post a Comment