<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Re: [HELP] IOS IPS -- Is the performance hit worth it? in Cisco</title>
<link>http://www.dslreports.com/forum/r18328248</link>
<description></description>
<language>en</language>
<pubDate>Wed, 11 Nov 2009 07:33:44 EDT</pubDate>
<lastBuildDate>Wed, 11 Nov 2009 07:33:44 EDT</lastBuildDate>

<item>
<title>Re: [HELP] IOS IPS -- Is the performance hit worth it?</title>
<link>http://www.dslreports.com/forum/remark,18329270</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> :  <BLOCKQUOTE><SMALL>quote:</SMALL><HR>However, ther are at least two current IOS images out for the C870's, one is Pi5 based, the other is Pi6 based<HR></BLOCKQUOTE>I wouldn't call pi6 out - it has not been released yet.  12.4(11)T is pi5.  Not sure what the number for pi6 will be when it is released.<br> <BLOCKQUOTE><SMALL>quote:</SMALL><HR>Both Pi5 and Pi6 were to be "merged", but that has been "delayed".<HR></BLOCKQUOTE>This makes no sense.  Pi5 and pi6 are different release of 12.4T.  Pi6 is pi5 plus additional features (and bug fixes) just like pi5 is pi4 (12.4(9)T) plus additional features and bug fixes.  "Merged" has no meaning.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18329270</guid>
<pubDate>Sun, 13 May 2007 21:18:29 EDT</pubDate>
</item>

<item>
<title>Re: [HELP] IOS IPS -- Is the performance hit worth it?</title>
<link>http://www.dslreports.com/forum/remark,18329019</link>
<description><![CDATA[<A HREF="/useremail/u/1128128"><b>TROLL131313</b></A> : This might help......<br><br>&raquo;<A HREF="http://www.cisco.com/warp/public/63/showproc_cpu.html" >www.cisco.com/warp/public/63/sho&middot;&middot;&middot;cpu.html</A><br><br>It gives a good brake down of the processes commands that are running.<br><br>What do your processes look like with out IPS on?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18329019</guid>
<pubDate>Sun, 13 May 2007 20:24:12 EDT</pubDate>
</item>

<item>
<title>Re: [HELP] IOS IPS -- Is the performance hit worth it?</title>
<link>http://www.dslreports.com/forum/remark,18328248</link>
<description><![CDATA[<A HREF="/useremail/u/601298"><b>jrpavel3</b></A> : Well I am still not much further forward even with 12.4(11)T2.<br><br>The CPU is still maxed out downloading at roughly 1MB/s.<br><br>What I had not noticed before was that it is interrupts and not cpu that is sapping the cpu. Eg, the cpus is at 95%, with 89% accounted for by interrupts.<br><br><div class="code"><PRE><span class="codetext">CPU utilization for five seconds: 95%/89%; one minute: 41%; five minutes: 12%<br>PID Runtime(ms)   Invoked      uSecs   5Sec   1Min   5Min TTY Process<br>  4     2232292    112872      19777  2.83%  1.26%  1.23%   0 Check heaps<br> 41     1101908    828463       1330  1.02%  0.99%  0.64%   0 COLLECT STAT COU<br> 77       50776      6442       7882  0.48%  0.10%  0.02%   2 Virtual Exec<br> 79      122432    136100        899  0.16%  0.13%  0.08%   0 IP Input<br> 47       28804   2023517         14  0.16%  0.03%  0.00%   0 Dot11 driver<br>211       21964    146202        150  0.16%  0.04%  0.01%   0 HyBridge Input P<br>  2        9992     33229        300  0.08%  0.01%  0.00%   0 Load Meter<br>207       16004   5152782          3  0.08%  0.02%  0.00%   0 PPP manager<br>213       10588    257205         41  0.08%  0.01%  0.00%   0 Spanning Tree<br>111        2224     82940         26  0.08%  0.00%  0.00%   0 ILMI Timer Proce</SPAN></PRE></DIV><br>I had expected the problem to be the cpu spending its time matching incoming traffic to the IPS signatures, but clearly something else is going on.<br><br>Does anyone have any pointers as to how to track this down?<br>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18328248</guid>
<pubDate>Sun, 13 May 2007 17:17:03 EDT</pubDate>
</item>

<item>
<title>Re: [HELP] IOS IPS -- Is the performance hit worth it?</title>
<link>http://www.dslreports.com/forum/remark,18099789</link>
<description><![CDATA[<A HREF="/useremail/u/880412"><b>tdoran</b></A> : <div class="bquote"><SMALL>said by godric :</SMALL><BR><BR>Can you point me at a Pi6 image?  I could not see other than the two images above.<br> </DIV>Most are "TEST", "ENGINEERING", or "SPECIAL BUILD", not in the "normal" public distribution method.  If you have a SMARTNET (and you really should) open up a TAC case, they will place one out there for you to grab.<br><br>Tim]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18099789</guid>
<pubDate>Sun, 01 Apr 2007 14:45:55 EDT</pubDate>
</item>

<item>
<title>Re: [HELP] IOS IPS -- Is the performance hit worth it?</title>
<link>http://www.dslreports.com/forum/remark,18099541</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Tim, Thanks.  I tried 12.4(11)T1 (and only the ios_basic sigs) and 12.4(9)T3 (and the 128Mb sigs, less the Unix sigs). IPS in either of those seems to halve throughput and max out the cpu.  There is also a significant increase in memory usage.<br><br>Can you point me at a Pi6 image?  I could not see other than the two images above.<br><br>Thanks.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18099541</guid>
<pubDate>Sun, 01 Apr 2007 13:45:02 EDT</pubDate>
</item>

<item>
<title>Re: [HELP] IOS IPS -- Is the performance hit worth it?</title>
<link>http://www.dslreports.com/forum/remark,18098203</link>
<description><![CDATA[<A HREF="/useremail/u/880412"><b>tdoran</b></A> : <div class="bquote"><SMALL>said by  jrpavel3 <A HREF="/useremail/u/601298"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><BR><BR>Thanks Tim.  Will do.<br>I hope that the improvements will extend to the 877.<br></DIV>All C870's have had some issues with thelast few Pi5 and Pi6 IOS images, Cisco is very well aware of this.<br><br><div class="bquote"><SMALL>said by  jrpavel3 <A HREF="/useremail/u/601298"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><BR><BR>I suspect that since disabling IPS makes such a dramatic difference, it is probably going to be a matter of waiting for IPS6 -- and an SDM to go with it.<br></DIV>Again, IOS IPS should not make a major impact, especially IOS IPS v5, since it is "lighter" than IOS IPS v4.  IOS IPS v5 uses a form of dynamic loading, thus not consuming as many resources.<br><br>However, ther are at least two current IOS images out for the C870's, one is Pi5 based, the other is Pi6 based (you can search on CCO if you want to know more of what the differences between the two tracks are in detail).  Both Pi5 and Pi6 were to be "merged", but that has been "delayed". <br><br><div class="bquote"><SMALL>said by  jrpavel3 <A HREF="/useremail/u/601298"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><BR><BR>I thought that I would just check that my ACLs, etc, were not being overzealous.<br> </DIV>With any of the last few IOS images, Pi5 or Pi6 track on the C870's, resources has been an issue.<br><br>Tim]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18098203</guid>
<pubDate>Sun, 01 Apr 2007 08:52:06 EDT</pubDate>
</item>

<item>
<title>Re: [HELP] IOS IPS -- Is the performance hit worth it?</title>
<link>http://www.dslreports.com/forum/remark,18097973</link>
<description><![CDATA[<A HREF="/useremail/u/601298"><b>jrpavel3</b></A> : Thanks Tim.  Will do.<br><br>I hope that the improvements will extend to the 877.<br><br>I suspect that since disabling IPS makes such a dramatic difference, it is probably going to be a matter of waiting for IPS6 -- and an SDM to go with it.<br><br>I thought that I would just check that my ACLs, etc, were not being overzealous.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18097973</guid>
<pubDate>Sun, 01 Apr 2007 06:24:47 EDT</pubDate>
</item>

<item>
<title>Re: [HELP] IOS IPS -- Is the performance hit worth it?</title>
<link>http://www.dslreports.com/forum/remark,18096812</link>
<description><![CDATA[<A HREF="/useremail/u/880412"><b>tdoran</b></A> : <div class="bquote"><SMALL>said by  jrpavel3 <A HREF="/useremail/u/601298"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><BR><BR>Thanks.<br>But IPS5 seems to be even more resource hungry than IPS4, so the benefits may be limited.  </DIV>That is not a true fact IOS IPS v5 is much less than IOS IPS v5, especially if many signatures are enabled.<br><br>However, the most current IOS images that support IOS IPS v5 have resource issue that are not related to IOS IPS v5.<br><br>A Pi6 type IOS image was to be available in late Feb. 2007, now it will be late May - June may offer some major improvements.  Also the IOS Pi6 images will enable additional IOS IPS engines that are not now available to the public.<br><br>If you have a SMARTNET support agreement (and you really should), open a TAC case on this, and the TAC engineer will help you "balance" resources" until the new images are available.  All CBAC, FW, IOS IPS and similar statements along with some BUFFER adjustments will have to be made at the IOS CLI by the TAC engineer to reduce resource load.<br><br>I have been working "test builds" of a Pi6 build for months.<br><br>Tim]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18096812</guid>
<pubDate>Sat, 31 Mar 2007 22:11:08 EDT</pubDate>
</item>

<item>
<title>Re: [HELP] IOS IPS -- Is the performance hit worth it?</title>
<link>http://www.dslreports.com/forum/remark,18095805</link>
<description><![CDATA[<A HREF="/useremail/u/601298"><b>jrpavel3</b></A> : Here it is:<br><br><div class="code"><PRE><span class="codetext">Cisco IOS Software, C870 Software (C870-ADVIPSERVICESK9-M), Version 12.4(9)T3, RELEASE SOFTWARE (fc3)<br>Technical Support: http://www.cisco.com/techsupport<br>Copyright (c) 1986-2007 by Cisco Systems, Inc.<br>Compiled Sat 24-Mar-07 03:56 by prod_rel_team<br> <br>ROM: System Bootstrap, Version 12.3(8r)YI3, RELEASE SOFTWARE<br> <br>router uptime is 1 day, 2 hours, 50 minutes<br>System returned to ROM by reload at 20:58:42 BST Fri Mar 30 2007<br>System restarted at 20:59:33 BST Fri Mar 30 2007<br>System image file is "flash:c870-advipservicesk9-mz.124-9.T3.bin"<br>Last reload reason: Reload Command<br> <br>This product contains cryptographic features and is subject to United<br>States and local country laws governing import, export, transfer and<br>use. Delivery of Cisco cryptographic products does not imply<br>third-party authority to import, export, distribute or use encryption.<br>Importers, exporters, distributors and users are responsible for<br>compliance with U.S. and local country laws. By using this product you<br>agree to comply with applicable laws and regulations. If you are unable<br>to comply with U.S. and local laws, return this product immediately.<br> <br>A summary of U.S. laws governing Cisco cryptographic products may be found at:<br>http://www.cisco.com/wwl/export/crypto/tool/stqrg.html<br> <br>If you require further assistance please contact us by sending email to<br>export@cisco.com.<br> <br>Cisco 877W (MPC8272) processor (revision 0x200) with 118784K/12288K bytes of memory.<br>Processor board ID FCZ1042406V<br>MPC8272 CPU Rev: Part Number 0xC, Mask Number 0x10<br>4 FastEthernet interfaces<br>1 ATM interface<br>1 802.11 Radio<br>128K bytes of non-volatile configuration memory.<br>36864K bytes of processor board System flash (Intel Strataflash)<br> <br>Configuration register is 0x3922<br> <br>------------------ show running-config ------------------<br> <br>Building configuration...<br> <br>Current configuration : 20774 bytes<br>!<br>! Last configuration change at 22:18:24 BST Sat Mar 31 2007 by xxx<br>! NVRAM config last updated at 19:54:10 BST Sat Mar 31 2007 by xxx<br>!<br>version 12.4<br>no service pad<br>service tcp-keepalives-in<br>service tcp-keepalives-out<br>service timestamps debug datetime msec localtime show-timezone<br>service timestamps log datetime msec localtime show-timezone<br>service password-encryption<br>service sequence-numbers<br>!<br>hostname router<br>!<br>boot-start-marker<br>boot system flash:c870-advipservicesk9-mz.124-9.T3.bin<br>boot-end-marker<br>!<br>security authentication failure rate 3 log<br>security passwords min-length 6<br>logging buffered 4096 debugging<br>logging console critical<br>enable secret 5 &lt;removed&gt;<br>!<br>aaa new-model<br>!<br>!<br>aaa authentication login default local<br>aaa authentication ppp default group radius<br>aaa authorization exec default local <br>aaa authorization network default group radius <br>aaa authorization network sdm_vpn_group_ml_1 group radius <br>aaa accounting exec default start-stop group radius<br>aaa accounting connection default start-stop group radius<br>aaa accounting resource default start-stop-failure group radius<br>!<br>aaa session-id common<br>!<br>resource policy<br>!<br>clock timezone GMT 0<br>clock summer-time BST recurring last Sun Mar 2:00 last Sun Oct 3:00<br>no ip source-route<br>ip icmp rate-limit unreachable 100<br>ip icmp rate-limit unreachable DF 1<br>ip cef<br>!<br>!<br>!<br>!<br>ip tcp ecn<br>ip tcp selective-ack<br>ip tcp window-size 65537<br>ip tcp synwait-time 10<br>no ip bootp server<br>ip domain name Company.local<br>ip name-server 192.168.&lt;x&gt;.&lt;server&gt;<br>ip ssh time-out 60<br>ip ssh authentication-retries 2<br>ip inspect tcp reassembly queue length 64<br>ip inspect name DEFAULT100 appfw DEFAULT100<br>ip inspect name DEFAULT100 ftp<br>ip inspect name DEFAULT100 h323<br>ip inspect name DEFAULT100 icmp<br>ip inspect name DEFAULT100 rcmd<br>ip inspect name DEFAULT100 realaudio<br>ip inspect name DEFAULT100 rtsp<br>ip inspect name DEFAULT100 esmtp<br>ip inspect name DEFAULT100 tftp<br>ip inspect name DEFAULT100 udp<br>ip inspect name DEFAULT100 ntp<br>ip inspect name DEFAULT100 http<br>ip inspect name DEFAULT100 https<br>ip inspect name DEFAULT100 fragment maximum 250 timeout 1<br>ip inspect name DEFAULT100 tcp<br>ip inspect name DEFAULT100 isakmp<br>ip inspect name DEFAULT100 ipsec-msft<br>ip inspect name DEFAULT100 l2tp<br>ip inspect name DEFAULT100 pptp<br>ip ips sdf location flash://sdmips.sdf<br>ip ips sdf location flash://128MB.sdf autosave<br>ip ips notify SDEE<br>ip ips name sdm_ips_rule<br>ip dhcp-server 192.168.&lt;x&gt;.&lt;server&gt;<br>vpdn enable<br>!<br>vpdn-group L2TP<br>! Default L2TP VPDN group<br> accept-dialin<br>  protocol l2tp<br>  virtual-template 1<br> no l2tp tunnel authentication<br> l2tp tunnel receive-window 256<br>!<br>!<br>appfw policy-name DEFAULT100<br>  application http<br>    strict-http action allow alarm<br>    port-misuse tunneling action allow alarm<br>!<br>password encryption aes<br>!<br>crypto pki trustpoint TP-self-signed-3534083426<br> enrollment selfsigned<br> subject-name cn=IOS-Self-Signed-Certificate-3534083426<br> revocation-check none<br> rsakeypair TP-self-signed-3534083426<br>!<br>crypto pki trustpoint titan<br> enrollment mode ra<br> enrollment url http://192.168.&lt;x&gt;.&lt;server&gt;:80/certsrv/mscep/mscep.dll<br> usage ike<br> password &lt;removed&gt;<br> subject-name CN=Me,O=Company<br> revocation-check crl none<br>!<br>!<br>crypto pki certificate chain TP-self-signed-3534083426<br> certificate self-signed 01<br>  &lt;removed&gt;<br>  quit<br>crypto pki certificate chain titan<br> certificate &lt;removed&gt;<br>  quit<br> certificate ca &lt;removed&gt;<br>  quit<br>no crypto engine onboard 0<br>!<br>crypto key pubkey-chain rsa<br> named-key realm-cisco.pub signature<br>  key-string<br>   30820122 300D0609 2A864886 F70D0101 01050003 82010F00 3082010A 02820101 <br>   00C19E93 A8AF124A D6CC7A24 5097A975 206BE3A2 06FBA13F 6F12CB5B 4E441F16 <br>   17E630D5 C02AC252 912BE27F 37FDD9C8 11FC7AF7 DCDD81D9 43CDABC3 6007D128 <br>   B199ABCB D34ED0F9 085FADC1 359C189E F30AF10A C0EFB624 7E0764BF 3E53053E <br>   5B2146A9 D7A5EDE3 0298AF03 DED7A5B8 9479039D 20F30663 9AC64B93 C0112A35 <br>   FE3F0C87 89BCB7BB 994AE74C FA9E481D F65875D6 85EAF974 6D9CC8E3 F0B08B85 <br>   50437722 FFBE85B9 5E4189FF CC189CB9 69C46F9C A84DFBA5 7A0AF99E AD768C36 <br>   006CF498 079F88F8 A3B3FB1F 9FB7B3CB 5539E1D1 9693CCBB 551F78D2 892356AE <br>   2F56D826 8918EF3C 80CA4F4D 87BFCA3B BFF668E9 689782A5 CF31CB6E B4B094D3 <br>   F3020301 0001<br>  quit<br>username xxx privilege 15 secret 5 &lt;removed&gt;<br>!<br>! <br>!<br>crypto isakmp policy 1<br> encr 3des<br> group 2<br> lifetime 900<br>!<br>crypto isakmp policy 2<br> encr 3des<br> authentication pre-share<br> group 2<br> lifetime 900<br>crypto isakmp key &lt;removed&gt; address 0.0.0.0 0.0.0.0 no-xauth<br>!<br>crypto ipsec security-association idle-time 900<br>!<br>crypto ipsec transform-set ESP-3DES-SHA-transport esp-3des esp-sha-hmac <br> mode transport<br>crypto ipsec transform-set ESP-3DES-SHA esp-3des esp-sha-hmac <br>!<br>crypto dynamic-map SDM_DYNMAP_1 1<br> description L2TP/IPSec<br> set transform-set ESP-3DES-SHA-transport <br> reverse-route<br>!<br>!<br>crypto map SDM_CMAP_1 isakmp authorization list sdm_vpn_group_ml_1<br>crypto map SDM_CMAP_1 client configuration address respond<br>crypto map SDM_CMAP_1 65535 ipsec-isakmp dynamic SDM_DYNMAP_1 <br>!<br>bridge irb<br>!<br>!<br>!<br>interface Null0<br> no ip unreachables<br>!<br>interface ATM0<br> no ip address<br> no ip redirects<br> no ip unreachables<br> no ip proxy-arp<br> ip accounting access-violations<br> ip route-cache flow<br> no atm ilmi-keepalive<br> dsl operating-mode auto <br>!<br>interface ATM0.1 point-to-point<br> description Internet$ES_WAN$$FW_OUTSIDE$<br> bandwidth 18147<br> ip address &lt;my ip address&gt; 255.255.248.0<br> ip access-group 101 in<br> ip verify unicast reverse-path 103<br> no ip redirects<br> no ip proxy-arp<br> ip accounting access-violations<br> ip mtu 1500<br> ip nbar protocol-discovery<br> ip flow ingress<br> ip flow egress<br> ip nat outside<br> ip inspect DEFAULT100 out<br> ip ips sdm_ips_rule in<br> ip ips sdm_ips_rule out<br> ip virtual-reassembly<br> no snmp trap link-status<br> atm route-bridged ip<br> atm route-bridged ipv6<br> pvc BeUnlimited 0/101 <br>  oam-pvc manage<br>  encapsulation aal5snap<br> !<br> ipv6 enable<br> ipv6 nd ra suppress<br> crypto map SDM_CMAP_1<br>!<br>interface FastEthernet0<br>!<br>interface FastEthernet1<br>!<br>interface FastEthernet2<br>!<br>interface FastEthernet3<br>!<br>interface Virtual-Template1 <br> description L2TP<br> ip unnumbered BVI1<br> no ip redirects<br> no ip proxy-arp<br> ip accounting access-violations<br> ip nbar protocol-discovery<br> ip flow ingress<br> ip flow egress<br> ip nat inside<br> ip virtual-reassembly<br> ip route-cache flow<br> ip tcp adjust-mss 1360<br> peer default ip address dhcp<br> ppp mtu adaptive<br> ppp authentication eap ms-chap-v2<br> ppp ipcp header-compression ack<br> ppp ipcp username unique<br> ppp timeout idle 600 either<br>!<br>interface Dot11Radio0<br> description Wireless interface<br> no ip address<br> no ip redirects<br> no ip unreachables<br> ip accounting access-violations<br> countermeasure tkip hold-time 5<br> !<br> encryption mode ciphers tkip <br> !<br> ssid Wireless<br>    authentication open <br>    authentication key-management wpa<br>    guest-mode<br>    wpa-psk ascii &lt;removed&gt;<br> !<br> world-mode dot11d country GB indoor<br> speed basic-1.0 basic-2.0 basic-5.5 6.0 9.0 basic-11.0 12.0 18.0 24.0 36.0 48.0 54.0<br> station-role root<br> no cdp enable<br> bridge-group 1<br> bridge-group 1 spanning-disabled<br>!<br>interface Vlan1<br> description $ETH-SW-LAUNCH$$INTF-INFO-HWIC 4ESW$$FW_INSIDE$<br> no ip address<br> no ip redirects<br> no ip unreachables<br> ip accounting access-violations<br> ip tcp adjust-mss 1452<br> bridge-group 1<br>!<br>interface BVI1<br> description LAN$ES_LAN$$FW_INSIDE$<br> ip address 192.168.&lt;x&gt;.1 255.255.255.0<br> ip access-group 100 in<br> no ip redirects<br> no ip proxy-arp<br> ip accounting access-violations<br> ip nbar protocol-discovery<br> ip flow ingress<br> ip flow egress<br> ip nat inside<br> ip virtual-reassembly<br> ip route-cache flow<br> ip tcp adjust-mss 1412<br>!<br>ip route 0.0.0.0 0.0.0.0 &lt;gateway&gt;<br>!<br>ip flow-top-talkers<br> top 25<br> sort-by bytes<br> cache-timeout 36000<br>!<br>ip http server<br>ip http authentication local<br>ip http secure-server<br>ip http timeout-policy idle 60 life 86400 requests 10000<br>ip nat inside source list 1 interface ATM0.1 overload<br>ip nat inside source static udp 192.168.&lt;x&gt;.&lt;server&gt; 5005 interface ATM0.1 5005<br>ip nat inside source static udp 192.168.&lt;x&gt;.&lt;server&gt; 1755 interface ATM0.1 1755<br>ip nat inside source static tcp 192.168.&lt;x&gt;.&lt;server&gt; 1755 interface ATM0.1 1755<br>ip nat inside source static tcp 192.168.&lt;x&gt;.&lt;server&gt; 554 interface ATM0.1 554<br>ip nat inside source static tcp 192.168.&lt;x&gt;.&lt;server&gt; 3389 interface ATM0.1 3389<br>ip nat inside source static tcp 192.168.&lt;x&gt;.&lt;server&gt; 1723 interface ATM0.1 1723<br>ip nat inside source static tcp 192.168.&lt;x&gt;.&lt;server&gt; 4125 interface ATM0.1 4125<br>ip nat inside source static tcp 192.168.&lt;x&gt;.&lt;server&gt; 444 interface ATM0.1 444<br>ip nat inside source static tcp 192.168.&lt;x&gt;.&lt;server&gt; 443 interface ATM0.1 443<br>ip nat inside source static tcp 192.168.&lt;x&gt;.&lt;server&gt; 25 interface ATM0.1 25<br>ip nat inside source static tcp 192.168.&lt;x&gt;.&lt;server&gt; 80 interface ATM0.1 80<br>!<br>logging trap debugging<br>logging 192.168.&lt;x&gt;.&lt;server&gt;<br>access-list 1 remark INSIDE_IF=BVI1<br>access-list 1 remark SDM_ACL Category=2<br>access-list 1 permit 192.168.&lt;x&gt;.0 0.0.0.255<br>access-list 100 remark auto generated by Cisco SDM Express firewall configuration<br>access-list 100 remark SDM_ACL Category=1<br>access-list 100 permit udp host 192.168.&lt;x&gt;.&lt;server&gt; eq 1645 host 192.168.&lt;x&gt;.1<br>access-list 100 permit udp host 192.168.&lt;x&gt;.&lt;server&gt; eq 1646 host 192.168.&lt;x&gt;.1<br>access-list 100 deny   ip 87.194.32.0 0.0.7.255 any<br>access-list 100 deny   ip host 255.255.255.255 any<br>access-list 100 deny   ip 127.0.0.0 0.255.255.255 any<br>access-list 100 permit gre any any log<br>access-list 100 permit ip any any<br>access-list 101 remark auto generated by Cisco SDM Express firewall configuration<br>access-list 101 remark SDM_ACL Category=1<br>access-list 101 deny   ip host 0.0.0.0 any log<br>access-list 101 deny   ip 10.0.0.0 0.255.255.255 any log<br>access-list 101 deny   ip 172.16.0.0 0.15.255.255 any log<br>access-list 101 deny   ip 192.168.0.0 0.0.255.255 any log<br>access-list 101 deny   ip 127.0.0.0 0.255.255.255 any log<br>access-list 101 deny   ip host 255.255.255.255 any log<br>access-list 101 deny   ip 169.254.0.0 0.0.255.255 any log<br>access-list 101 deny   ip 0.0.0.0 0.255.255.255 any log<br>access-list 101 permit tcp any host &lt;my ip address&gt; eq www<br>access-list 101 permit esp any host &lt;my ip address&gt;<br>access-list 101 permit udp any host &lt;my ip address&gt; eq isakmp<br>access-list 101 permit udp any host &lt;my ip address&gt; eq non500-isakmp<br>access-list 101 permit udp any host &lt;my ip address&gt; eq 5005<br>access-list 101 permit udp any host &lt;my ip address&gt; eq 1755<br>access-list 101 permit tcp any host &lt;my ip address&gt; eq 1755<br>access-list 101 permit tcp any host &lt;my ip address&gt; eq 554<br>access-list 101 permit tcp any host &lt;my ip address&gt; eq 3389<br>access-list 101 permit tcp any host &lt;my ip address&gt; eq 1723<br>access-list 101 permit gre any host &lt;my ip address&gt; log<br>access-list 101 permit tcp any host &lt;my ip address&gt; eq 4125<br>access-list 101 permit tcp any host &lt;my ip address&gt; eq 444<br>access-list 101 permit tcp any host &lt;my ip address&gt; eq 443<br>access-list 101 permit tcp any host &lt;my ip address&gt; eq smtp<br>access-list 101 permit icmp any host &lt;my ip address&gt; echo-reply<br>access-list 101 permit icmp any host &lt;my ip address&gt; time-exceeded<br>access-list 101 permit icmp any host &lt;my ip address&gt; unreachable<br>access-list 101 remark Auto generated by SDM for NTP (123) 0.uk.pool.ntp.org<br>access-list 101 permit udp host 213.2.4.80 eq ntp host &lt;my ip address&gt; eq ntp<br>access-list 101 remark Auto generated by SDM for NTP (123) 193.190.230.66<br>access-list 101 permit udp host 193.190.230.66 eq ntp host &lt;my ip address&gt; eq ntp<br>access-list 101 deny   icmp any any redirect log<br>access-list 101 deny   ip any any log<br>access-list 102 remark VTY Access-class list<br>access-list 102 remark SDM_ACL Category=1<br>access-list 102 permit ip 192.168.&lt;x&gt;.0 0.0.0.255 any<br>access-list 102 deny   ip any any<br>access-list 103 remark Log any unicast reverse path packets<br>access-list 103 remark SDM_ACL Category=1<br>access-list 103 remark Deny any packets that fail unicast reverse path<br>access-list 103 deny   ip any any log<br>snmp-server community &lt;removed&gt; RW<br>snmp-server community &lt;removed&gt; RO<br>no cdp run<br>!<br>!<br>!<br>radius-server host 192.168.&lt;x&gt;.&lt;server&gt; auth-port 1645 acct-port 1646 key 7 &lt;removed&gt;<br>!<br>control-plane<br>!<br>bridge 1 protocol ieee<br>bridge 1 route ip<br>banner exec ^C<br>% Password expiration warning.<br>-----------------------------------------------------------------------<br> <br>Cisco Router and Security Device Manager (SDM) is installed on this device and <br>it provides the default username "cisco" for  one-time use. If you have already <br>used the username "cisco" to login to the router and your IOS image supports the <br>"one-time" user option, then this username has already expired. You will not be <br>able to login to the router with this username after you exit this session.<br> <br>It is strongly suggested that you create a new username with a privilege level <br>of 15 using the following command.<br> <br>username &lt;myuser&gt; privilege 15 secret 0 &lt;mypassword&gt;<br> <br>Replace &lt;myuser&gt; and &lt;mypassword&gt; with the username and password you want to <br>use.<br> <br>-----------------------------------------------------------------------<br>^C<br>banner login ^CAuthorized access only!<br> Disconnect IMMEDIATELY if you are not an authorized user!^C<br>!<br>line con 0<br> no modem enable<br> transport output telnet<br> speed 115200<br>line aux 0<br> transport output telnet<br>line vty 0 4<br> access-class 102 in<br> transport input telnet ssh<br>!<br>scheduler max-task-time 5000<br>scheduler allocate 4000 1000<br>scheduler interval 500<br>ntp logging<br>ntp clock-period 17175097<br>ntp source BVI1<br>ntp server 193.190.230.66 source ATM0.1<br>ntp server 213.2.4.80 source ATM0.1<br>!<br>webvpn install svc flash:/webvpn/svc.pkg<br>end</SPAN></PRE></DIV>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18095805</guid>
<pubDate>Sat, 31 Mar 2007 19:03:08 EDT</pubDate>
</item>

<item>
<title>Re: [HELP] IOS IPS -- Is the performance hit worth it?</title>
<link>http://www.dslreports.com/forum/remark,18095740</link>
<description><![CDATA[<A HREF="/useremail/u/676954"><b>aryoba</b></A> : The CPU and memory increased utilization might or might not worth it, depends on what your objective here.<br><br>To have better understanding and avoid misunderstanding, can you post the full configuration of the router then?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18095740</guid>
<pubDate>Sat, 31 Mar 2007 18:48:16 EDT</pubDate>
</item>

<item>
<title>Re: [HELP] IOS IPS -- Is the performance hit worth it?</title>
<link>http://www.dslreports.com/forum/remark,18095711</link>
<description><![CDATA[<A HREF="/useremail/u/601298"><b>jrpavel3</b></A> : Thanks.<br><br>I have only posted an extract.  I have<br><br><div class="code"><PRE><span class="codetext">ip ips sdf location flash://sdmips.sdf<br>ip ips sdf location flash://128MB.sdf autosave<br>ip ips notify SDEE<br>ip ips name sdm_ips_rule</SPAN></PRE></DIV><br>I used Express for initial setup, but the rest has been moded by hand/SDM.<br><br>I realise that IPS and CBAC are different functions, but it seems that I can't have everything without maxing out the cpu and limiting performance.<br><br>I also have "ip verify unicast reverse-path" but it's not clear whether than means that I can drop the spoofing ACL entries, eg.<br><br>Looking forward to 2.4 -- SDM is a pretty good tool.  But IPS5 seems to be even more resource hungry than IPS4, so the benefits may be limited. The cisco web site claims that 12.4(11)T is 30% more cpu-hungry than 12.4(9)T.<br>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18095711</guid>
<pubDate>Sat, 31 Mar 2007 18:41:19 EDT</pubDate>
</item>

<item>
<title>Re: [HELP] IOS IPS -- Is the performance hit worth it?</title>
<link>http://www.dslreports.com/forum/remark,18095668</link>
<description><![CDATA[<A HREF="/useremail/u/880412"><b>tdoran</b></A> : You do not have IOS IPS enabled from configuration example provided, you do have Cisco SDM Express firewall enabled, and the "inspect" statements (if too many can slow things down.  Only relatation between Cisco SDM Express firewall and IOS IPS is that they both share and use a lot of "core" CBAC code deep within the IOS.<br><br>Also you seemed to have configured via SDM Express, try  upgrading to the full SDM, new SDM later this week, version 2.4.<br><br>Tim]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18095668</guid>
<pubDate>Sat, 31 Mar 2007 18:30:47 EDT</pubDate>
</item>

<item>
<title>[HELP] IOS IPS -- Is the performance hit worth it?</title>
<link>http://www.dslreports.com/forum/remark,18095478</link>
<description><![CDATA[<A HREF="/useremail/u/601298"><b>jrpavel3</b></A> : I am running an 877W with IOS 12.4(9)T3 (and I have also tried 12.4(11)T1).<br><br>DSL throughput with IPS is halved (900k/s instead of 1.7M/s) using the 128Mb.sdf<br><br>Is this normal?<br><br>I have an extensive ACL/firewall and NAT.<br><br><div class="code"><PRE><span class="codetext">ip inspect name DEFAULT100 appfw DEFAULT100<br>ip inspect name DEFAULT100 ftp<br>ip inspect name DEFAULT100 h323<br>ip inspect name DEFAULT100 icmp<br>ip inspect name DEFAULT100 rcmd<br>ip inspect name DEFAULT100 realaudio<br>ip inspect name DEFAULT100 rtsp<br>ip inspect name DEFAULT100 esmtp<br>ip inspect name DEFAULT100 tftp<br>ip inspect name DEFAULT100 udp<br>ip inspect name DEFAULT100 ntp<br>ip inspect name DEFAULT100 http<br>ip inspect name DEFAULT100 https<br>ip inspect name DEFAULT100 fragment maximum 250 timeout 1<br>ip inspect name DEFAULT100 tcp<br>ip inspect name DEFAULT100 isakmp<br>ip inspect name DEFAULT100 ipsec-msft<br>ip inspect name DEFAULT100 l2tp<br>ip inspect name DEFAULT100 pptp<br> <br>access-list 101 remark auto generated by Cisco SDM Express firewall configuration<br>access-list 101 remark SDM_ACL Category=1<br>access-list 101 deny   ip host 0.0.0.0 any log<br>access-list 101 deny   ip 10.0.0.0 0.255.255.255 any log<br>access-list 101 deny   ip 172.16.0.0 0.15.255.255 any log<br>access-list 101 deny   ip 192.168.0.0 0.0.255.255 any log<br>access-list 101 deny   ip 127.0.0.0 0.255.255.255 any log<br>access-list 101 deny   ip host 255.255.255.255 any log<br>access-list 101 deny   ip 169.254.0.0 0.0.255.255 any log<br>access-list 101 deny   ip 0.0.0.0 0.255.255.255 any log<br>access-list 101 permit tcp any host &lt;my ip address&gt; eq www<br>access-list 101 permit esp any host &lt;my ip address&gt;<br>access-list 101 permit udp any host &lt;my ip address&gt; eq isakmp<br>access-list 101 permit udp any host &lt;my ip address&gt; eq non500-isakmp<br>access-list 101 permit udp any host &lt;my ip address&gt; eq 5005<br>access-list 101 permit udp any host &lt;my ip address&gt; eq 1755<br>access-list 101 permit tcp any host &lt;my ip address&gt; eq 1755<br>access-list 101 permit tcp any host &lt;my ip address&gt; eq 554<br>access-list 101 permit tcp any host &lt;my ip address&gt; eq 3389<br>access-list 101 permit tcp any host &lt;my ip address&gt; eq 1723<br>access-list 101 permit gre any host &lt;my ip address&gt; log<br>access-list 101 permit tcp any host &lt;my ip address&gt; eq 4125<br>access-list 101 permit tcp any host &lt;my ip address&gt; eq 444<br>access-list 101 permit tcp any host &lt;my ip address&gt; eq 443<br>access-list 101 permit tcp any host &lt;my ip address&gt; eq smtp<br>access-list 101 permit icmp any host &lt;my ip address&gt; echo-reply<br>access-list 101 permit icmp any host &lt;my ip address&gt; time-exceeded<br>access-list 101 permit icmp any host &lt;my ip address&gt; unreachable<br>access-list 101 remark Auto generated by SDM for NTP (123) 0.uk.pool.ntp.org<br>access-list 101 permit udp host 213.2.4.80 eq ntp host &lt;my ip address&gt; eq ntp<br>access-list 101 remark Auto generated by SDM for NTP (123) 193.190.230.66<br>access-list 101 permit udp host 193.190.230.66 eq ntp host &lt;my ip address&gt; eq ntp<br>access-list 101 deny   icmp any any redirect log<br>access-list 101 deny   ip any any log</SPAN></PRE></DIV><br>Could anyone suggest any strategies for optimizing my setup?  Should I just dump IPS?<br>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18095478</guid>
<pubDate>Sat, 31 Mar 2007 17:36:54 EDT</pubDate>
</item>

</channel>
</rss>
