Maximum number of entries allowed for IP addresses and domain names in SSLV(SSL Visibility appliance) OS 5.4/5.5
search cancel

Maximum number of entries allowed for IP addresses and domain names in SSLV(SSL Visibility appliance) OS 5.4/5.5

book

Article ID: 431038

calendar_today

Updated On:

Products

ISG SSLV SSL Visibility Appliance Software

Issue/Introduction

How many IP address and domain name entries does SSLV support?

Resolution

Key Information on Limits and Performance:

  • Hard Limits: There is no coded hard limit enforced on the number of entries.
  • Historical Reference: An old Knowledge Base (KB) article for version 4.x stated a limit of 10,000 entries.  We confirmed a configuration of 100 lists with 10,000 items per list for PKI for 5.x, which was believed to be similar for domains and IP addresses. This limit was later raised to 255 lists.
    Old article for 4.x is here. Limit to IP address entries in IP address lists on SSL Visibility (SSLV) appliances
  • Performance Impact: While there is no hard limit, a massively large set of objects will impact policy evaluation performance.

 

Recommendation: 

  • If the customer starts to see performance or high utilization issues, they should consider consolidating these lists if possible. The impact is also dependent on overall traffic volume; for example, it would be a greater concern at 80% capacity than at 20% capacity.