Re: [c-nsp] Reflexive ACLs or CBAC on 6500

2008-01-29 Thread bill fumerola
On Fri, Jan 25, 2008 at 12:19:20PM +0200, Tassos Chatzithomaoglou wrote: Has anyone real world experience of using these 2 features (Reflexive ACLs or CBAC) on 6500 with MSFC2 (SUP2) or MSFC3 (SUP720)? depends on your environment. if you can limit the traffic that that would trigger the

Re: [c-nsp] Reflexive ACLs or CBAC on 6500

2008-01-28 Thread Tassos Chatzithomaoglou
Thanks Brian Roland, I guess i'll stick with the ACLs then. Imho, cisco should put out a warning when configuring these features. Regards, Tassos Brian Stiff (bstiff) wrote on 27/1/2008 7:07 πμ: Hi Tassos- While YMMV, the IOS Firewall product management team has been discouraging use of

Re: [c-nsp] Reflexive ACLs or CBAC on 6500

2008-01-26 Thread Roland Dobbins
On Jan 25, 2008, at 5:19 PM, Tassos Chatzithomaoglou wrote: If i understand right (according do the documentation) both are processed in software in the MSFC, so that's going to hurt a little. It has the potential to hurt a lot. I highly recommend that you not do this if you're passing

Re: [c-nsp] Reflexive ACLs or CBAC on 6500 (Tassos Chatzithomaoglou)

2008-01-26 Thread Brian Stiff (bstiff)
Hi Tassos- While YMMV, the IOS Firewall product management team has been discouraging use of IOS Firewall Inspection (CBAC) on the Cat6K for some time. For whatever reason, I can't locate the IOSFW EoL page, but please have a look at a link from last year:

[c-nsp] Reflexive ACLs or CBAC on 6500

2008-01-25 Thread Tassos Chatzithomaoglou
Has anyone real world experience of using these 2 features (Reflexive ACLs or CBAC) on 6500 with MSFC2 (SUP2) or MSFC3 (SUP720)? If i understand right (according do the documentation) both are processed in software in the MSFC, so that's going to hurt a little. Are there any hidden