10-16-2007 01:32 PM - edited 03-03-2019 07:12 PM
Hello,
On my Cisco 877 router (running in VPN mode) I have the ip nbar protocol-discovery enabled on the VLAN 1 interface. I also have Netflow on a local PC. When I run "show ip nbar protocol-discovery interface vlan 1" it shows that edonkey and skype are running through the interface!
I'm not sure how long the data is kept on the router or if it's refreshed every few minutes, but I have just run it when only 4 IP printers and 1 laptop are on the network and these 2 apps are running apparently. I have checked the laptop and can't find the P2P edonkey app or Skype app. Why is it shwing up as nbar is deep packet inspection?
10-22-2007 01:46 PM
Skype app, is Peer-to-Peer VoIP Client Software, are you running any VOICE related application.
Try this URL:
http://www.cisco.com/en/US/products/ps6441/products_configuration_guide_chapter09186a008064fb50.html
10-22-2007 11:23 PM
Once a protcol is found by NBAR, it shows the byte/packet counter that is matched against this.
I do not of the vaild aging time for these statistics but for testing you can clear the NBAR statistics and confirm whether the protocol is being discovered again. This can be done by using the following command clear ip nbar protocol-discovery
Also disabling and enabling ip nbar protocol-discovery will flush all the counters
HTH
Narayan
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: