[c-nsp] NBAR on 7600 - Internet Gateway

Joe Maimon jmaimon at ttec.com
Wed Dec 7 00:45:01 EST 2005



Kristian Larsson wrote:

> On Sun, Nov 20, 2005 at 03:54:38PM -0500, Ray Burkholder wrote:
> 
>>Quoting Kristian Larsson <kristian at juniks.net>:
>>
>>
>>>Or you can go Linux+l7-filter+opteron+pci-express
>>>NICs.
>>>
>>
>>Specifically what type of software would you use to do the filtering?
> 
> Linux kernel + l7 filter
> (http://l7-filter.sourceforge.net/).
> 
> Opteron has superior bandwidth and the PCI-express
> will allow you to do more than 2.8 million IOs per
> second (ie wirespeed at min size packets).
> 
>    Kristian
> _______________________________________________

Push all the customers causing you pain into a seperate vrf.

route through the linux box back into the 7609 global table.

Police/Shape on the linux box.




More information about the cisco-nsp mailing list