[nsp] Bogon Addresses

Gert Doering gert at greenie.muc.de
Wed Oct 22 16:46:56 EDT 2003


Hi,

On Wed, Oct 22, 2003 at 08:06:59AM +0300, M.Palis wrote:
>  What I am interesting about is whether their is a way to get some
> statistics on my routers about the traffic that is dropped due to bogon
> addresses.
> Does someone of you get such statistics and if yes how?

Send the traffic to a loopback interface (give the loopback an ip
network, "set ip next-hop <other ip from that loopback network>") 
and have an outgoing ACL on the loopback that does "deny ip any any log"
(or just counts it without logging).

Watch out for CPU load when doing deny/log.

gert

-- 
USENET is *not* the non-clickable part of WWW!
                                                           //www.muc.de/~gert/
Gert Doering - Munich, Germany                             gert at greenie.muc.de
fax: +49-89-35655025                        gert at net.informatik.tu-muenchen.de


More information about the cisco-nsp mailing list