Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Equipment Support » Hardware By Brand » Cisco » [Config] 871 & 12.4(15)T3 DebugsON ?
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
[Config] Firewall config or virus/spyware? »
« [H/W] 7609 & WS-X6724-SFP - Resolved  
AuthorAll Replies

TROLL131313

join:2004-12-21
Horsham, PA
·Comcast

reply to mazzy
Re: [Config] 871 & 12.4(15)T3 DebugsON ?

You are correct on the boot-up debug. IOS has to do this since it spits out info on the remote port on start up.

Have you tried the IPS migration wizard in SDM yet? It seems to work and it will even download the latest V5 signature pkg from cisco and convert them.

Overall the performance seems better now with IPS, tho time will tell.


MSN

join:2004-05-15
Osgoode, ON

Coincidentally, I'm testing my new 871 with 12.4(15)T3 and with IPS turned on both outbound and inbound and I'm seeing absolutely no performance difference with IPS on vs. off.

Speedtest.net and speakeasy.net/speedtest both give me approximately 4200 kbps down and 600 kbps up on my ADSL connection regardless of whether IPS is scanning the packets or not. I'm seeing all kinds of detailed IPS messages in my syslog as it's doing its thing too, so I know its working.

I'm also using ZBF (Zone-Based firewall). I'm impressed and a bit surprised.

/Eric

jrpavel3

join:2002-03-16
UK
If you show cpu history, you will see how hard your router is working

mr_dirt

join:2006-02-14
Denver, CO

reply to MSN
said by MSN See Profile :

I'm also using ZBF (Zone-Based firewall). I'm impressed and a bit surprised.

So, what are you impressed and surprised at? Performance?

Are you running the complete sig list?


MSN

join:2004-05-15
Osgoode, ON

I'm running the complete "basic" list per the SDM's recommendations. Since the 871 only has 128 MB RAM, the advanced list will cause memory faults when traffic is high.

That said, I've only disabled two signatures. Cisco recently announced a TTL vulnerability in their IOS and two of the signatures matched against this type of DoS attack. I was getting too many false positives (mainly from UPnP and dynamic routing protocol...basically IP multicast) so I turned 'em off.

As I said in my 1st post, what impresses me most is that througput doesn't seem to be affected in the least with the IPS engines (13 of them) all turned on.

/Eric

mr_dirt

join:2006-02-14
Denver, CO
Thanks for the details.


MSN

join:2004-05-15
Osgoode, ON
You're welcome.

Also, I'm running 384 signatures.

/Eric
Forums » Equipment Support » Hardware By Brand » Cisco[Config] Firewall config or virus/spyware? »
« [H/W] 7609 & WS-X6724-SFP - Resolved  


Saturday, 05-Dec 15:10:48 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [163] Comcast Releasing Promised Usage Meter
· [147] Avast Antivirus Has Gone Mad
· [127] Comcast Makes NBC Universal Acquisition Official
· [104] Graduate Student Unveils Sprint's GPS Sharing With Feds
· [101] Google Invades ISP, OpenDNS Turf With Google Public DNS
· [99] The Bandwidth Hog Does Not Exist
· [85] FCC Ponders Moving From PSTN To IP Voice
· [81] Latest Consumer Reports Survey Not Kind To AT&T
· [80] New Bill Aims To Limit ETFs
· [74] Sprint Defuses GPS Privacy Media Bomb
Most people now reading
· Wife might have to work in.... Iowa for a few months!!! [General Questions]
· False positive in Avast! or is it real? [Security]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· UPS - What do you people think happened? [General Questions]
· First commercial tool to crack BitLocker arrives (Updated) [Security]
· DNS options, what are YOU using? [TekSavvy]
· Windows 7 boot manager editing questions [Microsoft Help]
· [How to] Install Asterisk on an Asus WL-520GU router [VOIP Tech Chat]
· What is the spell hit cap for a lvl 80 full arcane spec mage [World of Warcraft]
· Farewell [Bell Canada]