cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
588
Views
0
Helpful
2
Replies

NBAR false positives?

jkeeffe
Level 2
Level 2

Nbar protocol discovery in a 7206 router shows traffic in the winmx and eDonkey class. Before I raise to much of a fuss with users I need to make sure that this isn't a false positive. Does NBAR only match on tcp/udp ports for these two applications, or does it do deeper inspection and match on other patterns?

I just want to make sure that other applications aren't using the eDonkey and winmax ports.

2 Replies 2

a.alekseev
Level 7
Level 7

I had an issue with NBAR and winmx.

Some traffic, which was not really wimux, was classified as winmx.

I'm having this issue now. NBAR shows lot of traffic as winmx, but there's no match on TCP port 6699, as the NBAR port-map shows. What did you use to identify this traffic?