<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Re: [Info] Inspection &#x26; performance in Cisco</title>
<link>http://www.dslreports.com/forum/r20752586</link>
<description></description>
<language>en</language>
<pubDate>Wed, 11 Nov 2009 12:07:38 EDT</pubDate>
<lastBuildDate>Wed, 11 Nov 2009 12:07:38 EDT</lastBuildDate>

<item>
<title>Re: [Info] Inspection &#x26; performance</title>
<link>http://www.dslreports.com/forum/remark,20752828</link>
<description><![CDATA[<A HREF="/useremail/u/1411064"><b>Sailing_Nut</b></A> : Hmmmmm. I didn't think I would need an entry since my DNS server is only a private one and does not have any DNS "duties" that are inbound from the Internet.<br><br>My web issues are that sites load slowly or not at all. If a site doesn't load if I refresh in IE it will load very quickly. Sometimes it takes several tries of refreshing to get a site to load.<br><br>One other question I just came up with in looking over my config is that I have "ip domain name wtbhome.net" This is not really a public domain name, it is just what I use internally on my network. Could this cause problems?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20752828</guid>
<pubDate>Mon, 07 Jul 2008 11:17:18 EDT</pubDate>
</item>

<item>
<title>Re: [Info] Inspection &#x26; performance</title>
<link>http://www.dslreports.com/forum/remark,20752787</link>
<description><![CDATA[<A HREF="/useremail/u/676954"><b>aryoba</b></A> : Without looking at your traffic inspection packet capture, I'm thinking that you may need to punch in line on your ACL 107 and set static PAT for your DNS server performance just like you set one for your FTP server. A lot of time such setup solves a lot of problem. :D<br><br>Btw, what was the web traffic issue anyway? :)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20752787</guid>
<pubDate>Mon, 07 Jul 2008 11:08:30 EDT</pubDate>
</item>

<item>
<title>Re: [Info] Inspection &#x26; performance</title>
<link>http://www.dslreports.com/forum/remark,20752706</link>
<description><![CDATA[<A HREF="/useremail/u/1411064"><b>Sailing_Nut</b></A> : WOW! You have a way better memory than I do!<br><br>I think I might be having some DNS problems now. (I'll go back and look for the solution.)<br><br>I do know that I'm having lots of problems with web traffic. A while ago I opened a ticket with Cisco & sent them Wire Shark captures. They said it was a problem with my using inspection and that my ISP (Verizon FiOS)was sending lots of out of order packets and that was causing the inspection to puke.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20752706</guid>
<pubDate>Mon, 07 Jul 2008 10:50:51 EDT</pubDate>
</item>

<item>
<title>Re: [Info] Inspection &#x26; performance</title>
<link>http://www.dslreports.com/forum/remark,20752586</link>
<description><![CDATA[<A HREF="/useremail/u/676954"><b>aryoba</b></A> : I recall sometime ago you had problem with your DNS server. I don't see the DNS-server-related router configuration anywhere. Therefore I'm not sure if you solve the DNS issue or not.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20752586</guid>
<pubDate>Mon, 07 Jul 2008 10:27:29 EDT</pubDate>
</item>

<item>
<title>Re: [Info] Inspection &#x26; performance</title>
<link>http://www.dslreports.com/forum/remark,20752283</link>
<description><![CDATA[<A HREF="/useremail/u/1411064"><b>Sailing_Nut</b></A> : I'm running 12.4(15)T1 on my router.<br><br>I'm stretching my memory a bit, but I think I needed to step up to this version because of a feature I'm using, but I can't 100% remember. Either that or the Cisco people tol me I needed to move up to it to solve a problem I was seeing.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20752283</guid>
<pubDate>Mon, 07 Jul 2008 09:13:19 EDT</pubDate>
</item>

<item>
<title>Re: [Info] Inspection &#x26; performance</title>
<link>http://www.dslreports.com/forum/remark,20751370</link>
<description><![CDATA[<A HREF="/useremail/u/635348"><b>rolande</b></A> : Nothing jumps out at me as a glaring issue with your config. What version and feature set of 12.4 IOS are you running? 12.4 is known to have lots of "issues". I personally downgraded one of my own routers to mainline 12.3 to avoid the pain and suffering. I wouldn't call 12.4 anywhere near prime time for deployment. It shouldn't ever hurt to play with new code at home, but in my case it did. ;)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20751370</guid>
<pubDate>Sun, 06 Jul 2008 23:59:20 EDT</pubDate>
</item>

<item>
<title>Re: [Info] Inspection &#x26; performance</title>
<link>http://www.dslreports.com/forum/remark,20750935</link>
<description><![CDATA[<A HREF="/useremail/u/1411064"><b>Sailing_Nut</b></A> : I have cleaned tings up in my router but if anything I seem to be experiencing reduced performance.<br><br>Si, I guess the best thing would be for me to post my entire config. and hope some of the smart folks here can spot a problem.<br><br><textarea name="code" class="text" cols=50 rows=10> &#012;Current configuration : 9341 bytes&#012;!&#012;version 12.4&#012;no service pad&#012;service tcp-keepalives-in&#012;service tcp-keepalives-out&#012;service timestamps debug datetime msec localtime show-timezone&#012;service timestamps log datetime msec localtime show-timezone&#012;service password-encryption&#012;service sequence-numbers&#012;no service dhcp&#012;!&#012;hostname Cisco851W&#012;!&#012;boot-start-marker&#012;boot-end-marker&#012;!&#012;logging buffered 51200&#012;logging console critical&#012;enable secret 5 $1$M30K$1A3NfHGhUOITkYS3.kHIc1&#012;!&#012;aaa new-model&#012;!&#012;!&#012;aaa authentication login default local&#012;aaa authentication login sdm_vpn_xauth_ml_1 local&#012;aaa authorization exec default local &#012;aaa authorization network sdm_vpn_group_ml_1 local &#012;!&#012;!&#012;aaa session-id common&#012;clock timezone PCTime -5&#012;clock summer-time PCTime date Apr 6 2003 2:00 Oct 26 2003 2:00&#012;! &#012;!&#012;crypto isakmp policy 1&#012; encr 3des&#012; authentication pre-share&#012; group 2&#012;!&#012;!&#012;crypto pki trustpoint TP-self-signed-2835392884&#012; enrollment selfsigned&#012; subject-name cn=IOS-Self-Signed-Certificate-2835392884&#012; revocation-check none&#012; rsakeypair TP-self-signed-2835392884&#012;!&#012;!&#012;crypto pki certificate chain TP-self-signed-2835392884&#012; certificate self-signed 01&#012;*************&#012;  quit&#012;!&#012;dot11 ssid wtbhome&#012;   vlan 1&#012;   authentication open &#012;   authentication key-management wpa&#012;   wpa-psk ascii 7 ************************&#012;!&#012;dot11 ssid wtbhome guest-mode&#012;!&#012;no ip source-route&#012;no ip dhcp use vrf connected&#012;ip dhcp excluded-address 10.10.10.1&#012;!&#012;ip dhcp pool sdm-pool&#012;   import all&#012;   network 10.10.10.0 255.255.255.248&#012;   default-router 10.10.10.1 &#012;   lease 0 2&#012;!&#012;!&#012;ip cef&#012;ip inspect log drop-pkt&#012;ip inspect name SDM_LOW cuseeme&#012;ip inspect name SDM_LOW dns&#012;ip inspect name SDM_LOW ftp&#012;ip inspect name SDM_LOW h323&#012;ip inspect name SDM_LOW icmp&#012;ip inspect name SDM_LOW imap&#012;ip inspect name SDM_LOW pop3&#012;ip inspect name SDM_LOW rcmd&#012;ip inspect name SDM_LOW realaudio&#012;ip inspect name SDM_LOW rtsp&#012;ip inspect name SDM_LOW esmtp&#012;ip inspect name SDM_LOW sqlnet&#012;ip inspect name SDM_LOW streamworks&#012;ip inspect name SDM_LOW tftp&#012;ip inspect name SDM_LOW tcp&#012;ip inspect name SDM_LOW udp&#012;ip inspect name SDM_LOW vdolive&#012;no ip bootp server&#012;ip domain name wtbhome.net&#012;ip ddns update method myupdate&#012; HTTP&#012;  add http://tim%40theborlands.us:2and2is5%40dynupdate.no-ip.com/nic/update%3Fhostname=borland.no-ip.info&#012;!&#012;!&#012;appfw policy-name SDM_MEDIUM&#012;  application http&#012;    strict-http action allow alarm&#012;    port-misuse p2p action reset alarm&#012;    port-misuse tunneling action allow alarm&#012;!&#012;!&#012;!&#012;username tborland privilege 15 secret 5 *******************************&#012;username timvpn password 7 *************************&#012;archive&#012; log config&#012;  hidekeys&#012;!&#012;!&#012;ip tcp synwait-time 10&#012;ip ssh time-out 60&#012;ip ssh authentication-retries 2&#012;!&#012;bridge irb&#012;!&#012;!&#012;interface Null0&#012; no ip unreachables&#012;!&#012;interface FastEthernet0&#012;!&#012;interface FastEthernet1&#012;!&#012;interface FastEthernet2&#012;!&#012;interface FastEthernet3&#012;!&#012;interface FastEthernet4&#012; description Outside WAN$FW_OUTSIDE$&#012; mac-address 0018.012f.0a95&#012; ip ddns update hostname borland.no-ip.info&#012; ip ddns update myupdate&#012; ip address dhcp client-id FastEthernet4&#012; ip access-group 107 in&#012; no ip redirects&#012; no ip unreachables&#012; no ip proxy-arp&#012; ip inspect SDM_LOW out&#012; ip nat outside&#012; ip virtual-reassembly&#012; ip route-cache flow&#012; duplex auto&#012; speed auto&#012; no cdp enable&#012;!&#012;interface Dot11Radio0&#012; no ip address&#012; no dot11 extension aironet&#012; !&#012; encryption mode ciphers tkip &#012; !&#012; encryption vlan 1 mode ciphers tkip &#012; !&#012; ssid wtbhome&#012; !&#012; speed basic-1.0 basic-2.0 basic-5.5 6.0 9.0 basic-11.0 12.0 18.0 24.0 36.0 48.0 54.0&#012; station-role root&#012; no cdp enable&#012; bridge-group 1&#012; bridge-group 1 subscriber-loop-control&#012; bridge-group 1 spanning-disabled&#012; bridge-group 1 block-unknown-source&#012; no bridge-group 1 source-learning&#012; no bridge-group 1 unicast-flooding&#012;!&#012;interface Dot11Radio0.1&#012; encapsulation dot1Q 1 native&#012; no cdp enable&#012; bridge-group 1&#012; bridge-group 1 subscriber-loop-control&#012; bridge-group 1 spanning-disabled&#012; bridge-group 1 block-unknown-source&#012; no bridge-group 1 source-learning&#012; no bridge-group 1 unicast-flooding&#012;!&#012;interface Vlan1&#012; description Internal network&#012; no ip address&#012; ip nat inside&#012; no ip virtual-reassembly&#012; ip tcp adjust-mss 1452&#012; bridge-group 1&#012; bridge-group 1 spanning-disabled&#012;!&#012;interface BVI1&#012; description Bridge to internal network$FW_INSIDE$&#012; ip address 192.168.0.1 255.255.255.0&#012; ip access-group 106 in&#012; no ip redirects&#012; no ip unreachables&#012; no ip proxy-arp&#012; ip nat inside&#012; ip virtual-reassembly&#012; ip route-cache flow&#012;!&#012;ip local pool SDM_POOL_1 192.168.0.5 192.168.0.10&#012;ip local pool vpnpool 192.168.1.1 192.168.1.10&#012;ip route 0.0.0.0 0.0.0.0 FastEthernet4&#012;!&#012;ip http server&#012;ip http access-class 2&#012;ip http authentication local&#012;ip http secure-server&#012;ip http timeout-policy idle 60 life 86400 requests 10000&#012;ip nat inside source list 1 interface FastEthernet4 overload&#012;ip nat inside source static tcp 192.168.0.2 20 interface FastEthernet4 20&#012;ip nat inside source static tcp 192.168.0.2 21 interface FastEthernet4 21&#012;ip nat inside source static tcp 192.168.0.54 27000 interface FastEthernet4 27000&#012;ip nat inside source list 111 interface FastEthernet4 overload&#012;!&#012;access-list 1 remark INSIDE_IF=BVI1&#012;access-list 1 remark SDM_ACL Category=2&#012;access-list 1 permit 192.168.0.0 0.0.0.255&#012;access-list 2 remark HTTP Access-class list&#012;access-list 2 remark SDM_ACL Category=1&#012;access-list 2 permit 192.168.0.0 0.0.0.255&#012;access-list 2 deny   any&#012;access-list 105 remark VTY Access-class list&#012;access-list 105 remark SDM_ACL Category=1&#012;access-list 105 permit ip 192.168.0.0 0.0.0.255 any&#012;access-list 105 deny   ip any any&#012;access-list 106 remark auto generated by SDM firewall configuration&#012;access-list 106 remark SDM_ACL Category=1&#012;access-list 106 permit udp any host 192.168.0.1 eq non500-isakmp&#012;access-list 106 permit udp any host 192.168.0.1 eq isakmp&#012;access-list 106 permit esp any host 192.168.0.1&#012;access-list 106 permit ahp any host 192.168.0.1&#012;access-list 106 deny   ip host 255.255.255.255 any&#012;access-list 106 deny   ip 127.0.0.0 0.255.255.255 any&#012;access-list 106 permit ip any any&#012;access-list 107 remark auto generated by SDM firewall configuration&#012;access-list 107 remark SDM_ACL Category=1&#012;access-list 107 permit tcp any any eq 27000&#012;access-list 107 permit tcp any any eq ftp&#012;access-list 107 permit tcp any any eq ftp-data&#012;access-list 107 deny   ip 192.168.0.0 0.0.0.255 any&#012;access-list 107 permit udp any eq bootps any eq bootpc&#012;access-list 107 permit icmp any any echo-reply&#012;access-list 107 permit icmp any any time-exceeded&#012;access-list 107 permit icmp any any unreachable&#012;access-list 107 deny   ip 10.0.0.0 0.255.255.255 any&#012;access-list 107 deny   ip 172.16.0.0 0.15.255.255 any&#012;access-list 107 deny   ip 192.168.0.0 0.0.255.255 any&#012;access-list 107 deny   ip 127.0.0.0 0.255.255.255 any&#012;access-list 107 deny   ip host 255.255.255.255 any&#012;access-list 107 deny   ip any any log&#012;access-list 111 deny   ip 192.168.0.0 0.0.0.255 192.168.1.0 0.0.0.255&#012;access-list 111 permit ip any any&#012;no cdp run&#012;!&#012;control-plane&#012;!&#012;bridge 1 protocol ieee&#012;bridge 1 route ip&#012;banner login ^C&#012;-----------------------------------------------------------------------&#012;Cisco Router and Security Device Manager (SDM) is installed on this device. &#012;This feature requires the one-time use of the username "cisco" &#012;with the password "cisco". The default username and password have a privilege level of 15.&#012; &#012;Please change these publicly known initial credentials using SDM or the IOS CLI. &#012;Here are the Cisco IOS commands.&#012; &#012;username &lt;myuser&gt;  privilege 15 secret 0 &lt;mypassword&gt;&#012;no username cisco&#012; &#012;Replace &lt;myuser&gt; and &lt;mypassword&gt; with the username and password you want to use. &#012; &#012;For more information about SDM please follow the instructions in the QUICK START &#012;GUIDE for your router or go to http://www.cisco.com/go/sdm &#012;-----------------------------------------------------------------------&#012;^C&#012;!&#012;line con 0&#012; no modem enable&#012; transport output telnet&#012;line aux 0&#012; transport output telnet&#012;line vty 0 4&#012; access-class 105 in&#012; privilege level 15&#012; transport input telnet ssh&#012;!&#012;scheduler max-task-time 5000&#012;scheduler allocate 4000 1000&#012;scheduler interval 500&#012;end&#012;</textarea><!--end code block-->]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20750935</guid>
<pubDate>Sun, 06 Jul 2008 22:15:42 EDT</pubDate>
</item>

<item>
<title>Re: [Info] Inspection &#x26; performance</title>
<link>http://www.dslreports.com/forum/remark,20744394</link>
<description><![CDATA[<A HREF="/useremail/u/676954"><b>aryoba</b></A> : Is there any other <i>ip inspect</i> command applied anywhere? I know some people apply <i>ip inspect</i> command on multiple interfaces or on the same interface with "in" and "out" simultaneously.<br><br>How about any ACL applied to any interface? If there is ACL on any interface, then it should match with the respective <i>ip inspect</i> command. When they don't match, then there will be performance issue on certain or all applications.<br><br>As how useful there are, it depends on how you configure the CBAC security as a whole. When you configure them properly, then you will have some decent security on your servers and the rest of machines within your network seamlessly without affecting performance.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20744394</guid>
<pubDate>Sat, 05 Jul 2008 04:53:10 EDT</pubDate>
</item>

<item>
<title>Re: [Info] Inspection &#x26; performance</title>
<link>http://www.dslreports.com/forum/remark,20734238</link>
<description><![CDATA[<A HREF="/useremail/u/1411064"><b>Sailing_Nut</b></A> : The biggest question I have (and didn't actually ask) is "does it affect performance to have inspection turned on for applications that I don't use."<br><br>Oh, I do have it set to "ip inspect SDM_LOW out" on my WAN interface.<br><br>Thanks!]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20734238</guid>
<pubDate>Wed, 02 Jul 2008 21:07:57 EDT</pubDate>
</item>

<item>
<title>Re: [Info] Inspection &#x26; performance</title>
<link>http://www.dslreports.com/forum/remark,20733093</link>
<description><![CDATA[<A HREF="/useremail/u/635348"><b>rolande</b></A> : And you do have it configured on an interface to actually inspect?<br><br>Assuming that is the case, you will definitely see a performance hit for doing inspection. It is different on each platform and based on the amount of traffic being passed. Best thing to do is monitor performance for a period of time with it on and then disable it on the interface and monitor for any differences in utilization. It would not be unexpected to see a 10-20% overhead or more in performance from inspection.<br><small>--<br>Scott, CCIE #14618 Routing & Switching<br>Ignorance is temporary...stupidity lasts forever!<br>&raquo;<A HREF="http://www.thewaystation.com/techref/tech.shtml" >www.thewaystation.com/techref/tech.shtml</A><br>&raquo;<A HREF="http://blog.thewaystation.com/" >blog.thewaystation.com/</A></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20733093</guid>
<pubDate>Wed, 02 Jul 2008 17:29:27 EDT</pubDate>
</item>

<item>
<title>Re: [Info] Inspection &#x26; performance</title>
<link>http://www.dslreports.com/forum/remark,20731645</link>
<description><![CDATA[<A HREF="/useremail/u/1411064"><b>Sailing_Nut</b></A> : Should have specified that I'm using an 851w router.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20731645</guid>
<pubDate>Wed, 02 Jul 2008 13:16:00 EDT</pubDate>
</item>

<item>
<title>[Info] Inspection &#x26; performance</title>
<link>http://www.dslreports.com/forum/remark,20731637</link>
<description><![CDATA[<A HREF="/useremail/u/1411064"><b>Sailing_Nut</b></A> : Hi,<br><br>I'm trying to boost my router's performance and I had a question on how much the IP inspection affecte performance and secondly how useful it is.<br><br>Here is the inspection section from my config:<br><br><textarea name="code" class="text" cols=50 rows=10>ip cef&#012;ip inspect log drop-pkt&#012;ip inspect name SDM_LOW cuseeme&#012;ip inspect name SDM_LOW dns&#012;ip inspect name SDM_LOW ftp&#012;ip inspect name SDM_LOW h323&#012;ip inspect name SDM_LOW icmp&#012;ip inspect name SDM_LOW imap&#012;ip inspect name SDM_LOW pop3&#012;ip inspect name SDM_LOW rcmd&#012;ip inspect name SDM_LOW realaudio&#012;ip inspect name SDM_LOW rtsp&#012;ip inspect name SDM_LOW esmtp&#012;ip inspect name SDM_LOW sqlnet&#012;ip inspect name SDM_LOW streamworks&#012;ip inspect name SDM_LOW tftp&#012;ip inspect name SDM_LOW tcp&#012;ip inspect name SDM_LOW udp&#012;ip inspect name SDM_LOW vdolive&#012;no ip bootp server&#012;</textarea><!--end code block-->]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20731637</guid>
<pubDate>Wed, 02 Jul 2008 13:15:16 EDT</pubDate>
</item>

</channel>
</rss>
