Resource Management limits the level of usage of shared resources on a device. Shared resources on a device include:
The Firewall Resource Management feature extends the zone-based firewall resource management from the class level to the
VRF level and the global level. Class-level resource management provides resource protection for firewall sessions at a class
level. For example, parameters such as the maximum session limit, the session rate limit, and the incomplete session limit
protect firewall resources (for example, chunk memory) and keep these resources from being used up by a single class.
When virtual routing and forwarding (VRF) instances share the same policy, a firewall session setup request from one VRF
instance can make the total session count reach the maximum limit. When one VRF consumes the maximum amount of resources on
a device, it becomes difficult for other VRF instances to share device resources. To limit the number of VRF firewall sessions,
you can use the Firewall Resource Management feature.
At the global level, the Firewall Resource Management feature helps limit the usage of resources at the global routing domain
by firewall sessions.