[c-nsp] Sup2T interface ACL limitations

Dobbins, Roland rdobbins at arbor.net
Mon Dec 16 10:02:53 EST 2013


On Dec 16, 2013, at 9:26 PM, Rolf Hanßen <nsp at rhanssen.de> wrote:

> Maybe it works if I use an ACL with 100k entries but it takes a minute to install.

In what topological situation do you need 100K entries?  Unless you're a very large wholesale transit network trying to enforce anti-spoofing for downstreams of your downstreams, do you really need that many entries?

-----------------------------------------------------------------------
Roland Dobbins <rdobbins at arbor.net> // <http://www.arbornetworks.com>

	  Luck is the residue of opportunity and design.

		       -- John Milton




More information about the cisco-nsp mailing list