[c-nsp] Bogon Filter - Least Resource/CPU intensive method?

Justin Shore justin at justinshore.com
Thu Mar 6 12:49:10 EST 2008


Jeff Kell wrote:
> Justin Shore wrote:
>> Personally I'm still using ACLs on my border routers.  At this point 
>> in time I want the ACE hit counters for those rogue packets
> 
> Hrmmm... will these show up in netflow in some identifiable fashion?

That's a good question.  I'm not sure if NF will get the chance to log 
the flows before the ACL drops them.  I'll check my flow dumps to see if 
I can figure that out.

Justin


More information about the cisco-nsp mailing list