republican-creole
Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Equipment Support » Hardware By Brand » Cisco » [Config] 871 & 12.4(15)T3 DebugsON ?
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
[Config] Firewall config or virus/spyware? »
« [H/W] 7609 & WS-X6724-SFP - Resolved  
AuthorAll Replies

mr_dirt

join:2006-02-14
Denver, CO

reply to MSN
Re: [Config] 871 & 12.4(15)T3 DebugsON ?

said by MSN See Profile :

I'm also using ZBF (Zone-Based firewall). I'm impressed and a bit surprised.

So, what are you impressed and surprised at? Performance?

Are you running the complete sig list?


MSN

join:2004-05-15
Osgoode, ON

I'm running the complete "basic" list per the SDM's recommendations. Since the 871 only has 128 MB RAM, the advanced list will cause memory faults when traffic is high.

That said, I've only disabled two signatures. Cisco recently announced a TTL vulnerability in their IOS and two of the signatures matched against this type of DoS attack. I was getting too many false positives (mainly from UPnP and dynamic routing protocol...basically IP multicast) so I turned 'em off.

As I said in my 1st post, what impresses me most is that througput doesn't seem to be affected in the least with the IPS engines (13 of them) all turned on.

/Eric

mr_dirt

join:2006-02-14
Denver, CO
Thanks for the details.


MSN

join:2004-05-15
Osgoode, ON
You're welcome.

Also, I'm running 384 signatures.

/Eric
Forums » Equipment Support » Hardware By Brand » Cisco[Config] Firewall config or virus/spyware? »
« [H/W] 7609 & WS-X6724-SFP - Resolved  


Friday, 04-Dec 09:06:48 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [163] Comcast Releasing Promised Usage Meter
· [142] Avast Antivirus Has Gone Mad
· [107] Comcast Makes NBC Universal Acquisition Official
· [104] Graduate Student Unveils Sprint's GPS Sharing With Feds
· [88] Google Invades ISP, OpenDNS Turf With Google Public DNS
· [81] Latest Consumer Reports Survey Not Kind To AT&T
· [70] Baltimore To Ban Lazy Cable Installs
· [69] Sprint Defuses GPS Privacy Media Bomb
· [68] FCC Ponders Moving From PSTN To IP Voice
· [64] Broadband Killed The Game Console
Most people now reading
· False positive in Avast! or is it real? [Security]
· Do I have a problem due to AVAST? [Security]
· Windows 7 boot manager editing questions [Microsoft Help]
· [Rant] Disrespect of PTO [Rants, Raves, and Praise]
· Connecting to Google Voice Via SIP [VOIP Tech Chat]
· Extjs grid combo box. [Webmasters and Developers]
· IPComms Free DIDs now with sip registration maybe?? [VOIP Tech Chat]
· [WIN7] Outlook express under Windows 7? [Microsoft Help]
· Linux is terrorist - according to MS... [All Things Unix]