<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Has anyone been able to correlate performance issues due to the number of security rules present? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/has-anyone-been-able-to-correlate-performance-issues-due-to-the/m-p/2750#M2049</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I was thinking about writing very specific security rules for around 15 hosts.&amp;nbsp; The rules would essentially whitelist traffic by destination ips and application.&amp;nbsp; I am somewhat concerned that adding this many additional rules could potentially slow traffic down an appreciable amount for traffic that would match on rules below these.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has anyone run into issues with performance due to too many security rules?&amp;nbsp; I was able to find this post but not much else on the topic - &lt;A href="https://live.paloaltonetworks.com/message/41802"&gt;Slow Performanced Based on Order of ACL Rules&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 10 Dec 2014 22:33:59 GMT</pubDate>
    <dc:creator>bgirdner</dc:creator>
    <dc:date>2014-12-10T22:33:59Z</dc:date>
    <item>
      <title>Has anyone been able to correlate performance issues due to the number of security rules present?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/has-anyone-been-able-to-correlate-performance-issues-due-to-the/m-p/2750#M2049</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I was thinking about writing very specific security rules for around 15 hosts.&amp;nbsp; The rules would essentially whitelist traffic by destination ips and application.&amp;nbsp; I am somewhat concerned that adding this many additional rules could potentially slow traffic down an appreciable amount for traffic that would match on rules below these.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has anyone run into issues with performance due to too many security rules?&amp;nbsp; I was able to find this post but not much else on the topic - &lt;A href="https://live.paloaltonetworks.com/message/41802"&gt;Slow Performanced Based on Order of ACL Rules&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Dec 2014 22:33:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/has-anyone-been-able-to-correlate-performance-issues-due-to-the/m-p/2750#M2049</guid>
      <dc:creator>bgirdner</dc:creator>
      <dc:date>2014-12-10T22:33:59Z</dc:date>
    </item>
    <item>
      <title>Re: Has anyone been able to correlate performance issues due to the number of security rules present?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/has-anyone-been-able-to-correlate-performance-issues-due-to-the/m-p/2751#M2050</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;15 should not be an issue depending on the total rules you have, what inspection policies you have running, and which device you are using.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just make sure you use your best practices like making sure your m&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;ost used rules are higher in the policy without shadowing other rules.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The only time we have encountered a resource issue of any kind is when we had an improperly formatted Data Filter but even then we didn't notice a performance hit, just high CPU.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Dec 2014 14:10:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/has-anyone-been-able-to-correlate-performance-issues-due-to-the/m-p/2751#M2050</guid>
      <dc:creator>Dz3015</dc:creator>
      <dc:date>2014-12-11T14:10:46Z</dc:date>
    </item>
  </channel>
</rss>

