[c-nsp] IPv6 nd table on the 6500

Frank Bulk frnkblk at iname.com
Fri May 6 02:20:37 EDT 2011


What about in the 12.2SR code line?

Frank

-----Original Message-----
From: cisco-nsp-bounces at puck.nether.net
[mailto:cisco-nsp-bounces at puck.nether.net] On Behalf Of Tóth András
Sent: Thursday, May 05, 2011 8:26 AM
To: Phil Mayers
Cc: cisco-nsp at puck.nether.net
Subject: Re: [c-nsp] IPv6 nd table on the 6500

There are improvements made already in the following:
CSCtn78957 - High CPU seen with large IPv6 neighbor table

Integrated in SXI6 already.

Andras


On Thu, May 5, 2011 at 9:08 AM, Phil Mayers <p.mayers at imperial.ac.uk> wrote:
> On 05/05/2011 07:46 AM, Saku Ytti wrote:
>
>> Speaking of ND entries, they appear to carry significant new DoS vector
>> which
>> is rather hard to fix and it appears that not even new gear have given it
>> much
>> thought at all.
>>
>>
>
> I saw some IOS roadmap stuff for IPv6 ND DoS protection recently - 2-phase
> (1: global "prevent ND DoS", 2: per-interface "Prevent") so Cisco are at
> least aware of it.
> _______________________________________________
> cisco-nsp mailing list  cisco-nsp at puck.nether.net
> https://puck.nether.net/mailman/listinfo/cisco-nsp
> archive at http://puck.nether.net/pipermail/cisco-nsp/
>

_______________________________________________
cisco-nsp mailing list  cisco-nsp at puck.nether.net
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/




More information about the cisco-nsp mailing list