Re: [nsp] TCP connections randomly reset

From: Gert Doering (gert@greenie.muc.de)
Date: Thu Aug 09 2001 - 08:29:22 EDT


Hi,

On Wed, Aug 08, 2001 at 06:46:36PM +0200, Blaz Zupan wrote:
> > > We don't run (and don't plan to run) the firewall feature set on our backbone
> > > routers.
> >
> > You don't have to. This is done with CAR, and it actually works.
>
> Hey, amazingly, one finds new Cisco features every day. I though such features
> were only part of Firewall feature set. I'm positively surprised.

Surprises every day is describng it quite well :-) - up to now I always
thought "same software will have same features on 7200 and 7500" (modulo
hardware things, like dCEF not being useful on 7200s). Wrong, the 7500
with 12.0(17)S1 doesn't have the "match protocol http"...:

Cisco-F-V(config-cmap)#class-map match-any code-red
Cisco-F-V(config-cmap)# match protocol http url "*/default.ida*"
                                        ^
                                        % Invalid input detected at '^' marker.

... while our 7200s with 12.0(14)S3, 12.0(14)S and 12.0(17)S "just do
it", as already reported.

*Interesting* indeed...

gert

-- 
USENET is *not* the non-clickable part of WWW!
                                                           //www.muc.de/~gert/
Gert Doering - Munich, Germany                             gert@greenie.muc.de
fax: +49-89-35655025                        gert.doering@physik.tu-muenchen.de



This archive was generated by hypermail 2b29 : Sun Aug 04 2002 - 04:12:48 EDT