[c-nsp] ACL versus service-policy with drop condition

Luis Miguel Cruz Miranda luismcm at imasd.net
Sat Aug 10 10:33:30 EDT 2013


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

I am thinking on replace a big ingress ACL at the edge of the network
with a service-policy sticky with several class-map and split the big
ACL in several ACLs called from different class-maps.

Another reason is becuase I want to reuse/recall those class-maps from
another service-policy for other interfaces.

So, said that, I would like to know the experiences or handincaps on
that idea. From the perspective of the management as well from the
perspective of the perfomance/cpu.

Platform is 7201.
IOS is 12.4

Thanks in advance.

- -- 
Luis Miguel Cruz Miranda
GPG 0x6C08F418

-----BEGIN PGP SIGNATURE-----

iQEcBAEBAgAGBQJSBk80AAoJEBosOHBsCPQYo1YH/3dC8FcF8Z4dUWYK/AmBhlBr
6EtnGxQNqdTzQWsmZwq0/f5TlRNzaCjw4NMzG7Vxxicw2+d7Zef/u7TwSw2ajdNQ
DjIMmXw928BDqvcZpyhW0sR2KGDj5oDaZRKEU7cJsmCogjbPterm0PFEAdntOmlw
/vfhwzzgpzzlLOUFvnzwVIqtDRm1lfhYrmeJ0LFi4ckn7Tx2BDLbhWAwaGbNVL8/
5RoOc7i0p0F0EV0l08GGP1r87OW5HKW+s87KzRsokVPX6jPgG4ocJkegQvLZVBxZ
0PIbtNdoGYSQ0CVNOy4C+zeDjtumj2uKuUjGJVdNexlShtos3qaE2RUJ6K80aJ0=
=CHwe
-----END PGP SIGNATURE-----


More information about the cisco-nsp mailing list