[c-nsp] 2821, 2851, 3825, 3845 benchmarks or lack thereof.

Łukasz Bromirski lukasz at bromirski.net
Sun Jan 29 04:22:12 EST 2006


Christopher J. Wolff wrote:
> So if you had a clean sheet of paper, and since you are designing for
> profitability reasons you were going to deploy a 3825 to terminate your two
> DS3's at the edge.  Since the 3825 has no (D)DoS mitigation capabilities
> what are you going to deploy in front of or behind it to handle DoS?  

I already provided a solution - 3825 is ISR (as are 18xx, 28xx and
38xx), so control-plane policing can be used. It will work for full
pipe of DS3 traffic without a problem.

If You're looking for SP-type (D)DoS mitigation, there's always Cisco
Guard and Traffic Analyzer to help protect assets behind 3825. TA
can be installed in Your network and Guard in SP colocation in front of
Your DS3's, to help scrub all the trashy traffic before it fills up
Your pipe.

-- 
this space was intentionally left blank    |            Łukasz Bromirski
you can insert your favourite quote here   |        lukasz:bromirski,net


More information about the cisco-nsp mailing list