Re: NBAR and performance

From: micky (micky@apol.com.tw)
Date: Thu Aug 09 2001 - 19:40:03 EDT


Hi
    Reference URL
    http://www.cisco.com/warp/public/63/nbar_acl_codered.shtml
    I am ISP and suffering from code red attack, so we take cisco solutiuon
to block it to see if work

          Micky

----- Original Message -----
From: "Andrew Dorsett" <zerocool@netpath.net>
To: <cisco-nsp@puck.nether.net>
Sent: Friday, August 10, 2001 4:40 AM
Subject: NBAR and performance

> Hey, I'm looking at the NBAR solution for stopping Code Red and actually
> do traffic filtering. I know this is a performance hit, but exactly how
> hard and what are the limits? Can it take up to a T3 of data, or
> more? Amazing that this hasn't been used on the edge right before
> customer machines to temporarly let the worm die off. I know everyone is
> worried about performance, but what exactly is the packet delay?
>
> Thanks,
> Andrew
> ---
> <zerocool@netpath.net>
> http://www.andrewsworld.net/
> ICQ: 2895251
> Cisco Certified Network Associate
> Development Assistant: Netpath/Stratonet, Inc.
> (http://www.netpath.net/)
> Email: dorsett@netpath.net
>
> "Learn from the mistakes of others. You won't live long enough to make all
of them yourself."
>



This archive was generated by hypermail 2b29 : Sun Aug 04 2002 - 04:12:48 EDT