[c-nsp] Service Policy limitation

Tantsura, Jeff jeff.tantsura at capgemini.com
Thu Oct 7 11:53:53 EDT 2004



and DCEF enabled

Jeff

-----Original Message-----
From: cisco-nsp-bounces at puck.nether.net
[mailto:cisco-nsp-bounces at puck.nether.net] On Behalf Of Rodney Dunn
Sent: Thursday, October 07, 2004 4:37 PM
To: Amol Sapkal
Cc: cisco-nsp
Subject: Re: [c-nsp] Service Policy limitation

Yes you can do that.

To block on URL's require NBAR.

Rodney


On Tue, Oct 05, 2004 at 07:06:57PM +0530, Amol Sapkal wrote:
> On Tue, 5 Oct 2004 08:48:03 -0400, Rodney Dunn <rodunn at cisco.com>
wrote:
> > What are you trying to do with it?
> >
>
> Actually, I dont see a need to implement it on a FA on a production
> network for queuing(queuing will come in picture on exit interfaces),
> but I was looking at a solution of:
> 1.blocking HTTP urls and hosts on a service policy and try to apply it

> on the FA.
> 2.limiting tcp syn floods.
>
>
> The bandwidth stmt was asked in regards with point 2.
>
> Another problem is, I am already running CAR on the fa port.
>
>
> >
> >
> > On Tue, Oct 05, 2004 at 12:35:06PM +0530, Amol Sapkal wrote:
> > > Guys,
> > > I am trying to figure out hard, is it possible to apply a service
> > > policy on an gig or a Fa port?
> > >
> > > If yes, will it really enhance performance (considering the
> > > bandwidth available on an ethernet port is huge)
> > >
> > > I do have quiet a number of 7513s, but all are in production and
> > > cant try it out there.
> > > --
> > > Warm Regds,
> > >
> > > Amol Sapkal
> > >
> > > ------------------------------------------------------------------
> > > -- An eye for an eye makes the whole world blind
> > > - Mahatma Gandhi
> > > ------------------------------------------------------------------
> > > -- _______________________________________________
> > > cisco-nsp mailing list  cisco-nsp at puck.nether.net
> > > https://puck.nether.net/mailman/listinfo/cisco-nsp
> > > archive at http://puck.nether.net/pipermail/cisco-nsp/
> >
>
>
> --
> Warm Regds,
>
> Amol Sapkal
>
> --------------------------------------------------------------------
> An eye for an eye makes the whole world blind
> - Mahatma Gandhi
> --------------------------------------------------------------------
_______________________________________________
cisco-nsp mailing list  cisco-nsp at puck.nether.net
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/

This message contains information that may be privileged or confidential and is the property of the Capgemini Group. It is intended only for the person to whom it is addressed. If you are not the intended recipient,  you are not authorized to read, print, retain, copy, disseminate,  distribute, or use this message or any part thereof. If you receive this  message in error, please notify the sender immediately and delete all  copies of this message.




More information about the cisco-nsp mailing list