[c-nsp] Peer-to-peer NBAR rules

Church, Chuck cchurch at multimax.com
Mon Oct 2 15:44:01 EDT 2006


Anyone have a decent set of NBAR 'match protocol' rules that they're
willing to share that cover all the keywords beyond just the protocol?
I've got:
 
class-map match-any File-Sharing
 match protocol edonkey
 match protocol gnutella
 match protocol kazaa2
 match protocol napster
 match protocol winmx

On a 2650 running 12.4(9) mainline.  I know some of the protocols
support additional protocols like Gnutella:
 
xxx2650(config-cmap)#match pro gnutella ?
  file-transfer  Match file transfer stream
  <cr>
 
xxx2650(config-cmap)#match pro gnutella file
xxx2650(config-cmap)#match pro gnutella file-transfer ?
  WORD  Enter a string as the sub-protocol parameter
 
I'm looking to catch as many of the current popular file sharing/P2P
apps as possible, as this is supporting a wireless ISP (Wimax) with
really limited bandwidth.
 
Thanks in advance,
 
Chuck
 


More information about the cisco-nsp mailing list