[c-nsp] Filtering on sender IP#

Rodney Dunn rodunn at cisco.com
Tue Apr 12 10:16:44 EDT 2005


You can do it per-interface or globally via
CoPP.

http://www.cisco.com/en/US/products/sw/iosswrel/ps1838/products_feature_guide09186a00801afad4.html

We are working very hard to try and push the filtering down
in hardware with CoPP and there will be more developments in this
area as we move forward so it would be a good idea to become
familar with this conept.

Rodney


On Tue, Apr 12, 2005 at 04:05:34PM +0200, Mikael Carlander wrote:
> Is there any way of filtering on sender IP#?
> For example: If I want to minimise the impact on the router from illicit
> admin-connections (TCP-syn-flood) by blocking certain IP#, on line card
> level, from connecting to the router.
> 
> In hope of guidence
> 
> Mikael Carlander
> rip at kth.se
> 
> 
> 
> _______________________________________________
> cisco-nsp mailing list  cisco-nsp at puck.nether.net
> https://puck.nether.net/mailman/listinfo/cisco-nsp
> archive at http://puck.nether.net/pipermail/cisco-nsp/


More information about the cisco-nsp mailing list