[c-nsp] Modern BGP peering border router and DDoS attack defense recommendations?

Arie Vayner arievayner at gmail.com
Sat Jun 11 09:26:38 EDT 2005


The 3550 can do L4 ACL's (i.e. not only IP addresses, but also
protocol and port numbers)
Arie

On 6/11/05, Gert Doering <gert at greenie.muc.de> wrote:
> Hi,
> 
> On Sat, Jun 11, 2005 at 12:33:12PM +1000, David J. Hughes wrote:
> > before it made it to the 7200.  They did the job very well.  We have
> > since upgraded them to 3550s for the more flexible L3 ACLs and they
> > give us everything we need - hardware based layer 3 ACL's in front of a
> > "real" router.
> 
> Can the 3550 do L3 filtering on switched traffic?
> 
> (I know the 2950 can, which is really cool - no need to carry all the
> BGP routes on the "switch" device, but still be able to put filters on
> it).
> 
> gert
> --
> USENET is *not* the non-clickable part of WWW!
>                                                           //www.muc.de/~gert/
> Gert Doering - Munich, Germany                             gert at greenie.muc.de
> fax: +49-89-35655025                        gert at net.informatik.tu-muenchen.de
> _______________________________________________
> cisco-nsp mailing list  cisco-nsp at puck.nether.net
> https://puck.nether.net/mailman/listinfo/cisco-nsp
> archive at http://puck.nether.net/pipermail/cisco-nsp/
>



More information about the cisco-nsp mailing list