cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1281
Views
5
Helpful
9
Replies

Throughput of IDSM-2

a12288
Level 3
Level 3

Cisco Doc says the IDSM-2's throughput is 600Mbps in promiscuous mode, so what throughput I would get if I just send traffic to one data port.

2 Accepted Solutions

Accepted Solutions

attmidsteam
Level 1
Level 1

From the real-world note: We have numerous Cisco IDS devices, from 4215s up through 4250XLs and IDSM-2s. None of them meet their rated numbers, most start dropping packets at 1/3 of their claimed capacity. This is even after several TAC cases and extensive investigation by TAC engineers and internal developers. Maybe if you shut of 90% of signatures you could get there. Don't believe the hype.

View solution in original post

edwakim
Cisco Employee
Cisco Employee

Hi,

It will still be 600Mbps.

So you CAN still overload the sensor by sending traffic to one interface.

Thank you.

Edward

View solution in original post

9 Replies 9

edwakim
Cisco Employee
Cisco Employee

600Mbps limit is for the sensor. Even though it has two data ports (10/100/1000 port each), combined traffic sent to the interface(s) should not exceed 600Mbps.

Thank you.

Edward

thanks for your prompt replay, does it mean I could and would have 600Mbps throughput if I am going to use one data port only? thanks again.

No problem.

Each interface can take up to 1000 Mbps, but sensor can only handle 600 Mbps.

The reason that we have two dataports is for the inline mode.

Thank you.

Edward

Not applicable

attmidsteam
Level 1
Level 1

From the real-world note: We have numerous Cisco IDS devices, from 4215s up through 4250XLs and IDSM-2s. None of them meet their rated numbers, most start dropping packets at 1/3 of their claimed capacity. This is even after several TAC cases and extensive investigation by TAC engineers and internal developers. Maybe if you shut of 90% of signatures you could get there. Don't believe the hype.

thanks, this is what I need to know (behind the hype) before we would issue a PO.

edwakim
Cisco Employee
Cisco Employee

Hi,

It will still be 600Mbps.

So you CAN still overload the sensor by sending traffic to one interface.

Thank you.

Edward

Its 600Mbps if you're in Passive mode, and only 500Mbps if its Inline.

You are correct.

More information can be found here.

http://www.cisco.com/en/US/products/hw/modules/ps2706/products_data_sheet09186a00801e55dd.html

Thank you.

Edward

Review Cisco Networking products for a $25 gift card