cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
4508
Views
4
Helpful
6
Replies

how to enable NBAR

mkoch
Level 4
Level 4

Hi !

Do i have to enable "ip nbar protocol-discovery" on an interface i want to use NBAR on to classify traffic or is that command just used for statistics ?

Thanks,

Michael

6 Replies 6

dotoni
Level 1
Level 1

The "ip nbar protocol-discovery" command is applied on an interface to discover transitting traffic for all protocols known to NBAR. To display the gathered statistics, use the "show ip nbar protocol-discovery" command.

To enable NBAR do the following:

enable CEF, create a class-map to classify the protocol or application, create a policy-map for the class and attach the policy to an interface (service-policy command).

Check out this link: (watch the wrap)

http://www.cisco.com/univercd/cc/td/doc/product/software/ios122/122newft/122t/122t8/dtnbarad.htm#xtocid20

Dot

Sorry, I didn't answer your specific question in my last post. You do not need to explicitly invoke the "ip nbar protocol-discovery" command.

Dot

3gschalmo
Level 1
Level 1

Yes you have to type that on any interface that you want to use NBAR on. If you do not it will not work.

I have configured NBAR several times and never had to type it on the interface. I only typed the service policy command on the interface. I only used the protocol-discovery command later to view and verify the traffic pattern (with the show command).

It doesn't hurt typing in the command anyway, at least to give an indication of the traffic pattern (if you have no other way of doing that) before applying NBAR.

Dot

Hi !

This is why i was asking... the docs state neither "have to" nor "optional" and there seem to be a lot of disageeing about this...

Could maybe someone from cisco ask at development ? AND update the docs ?

Thanks everybody,

Michael

salshei
Cisco Employee
Cisco Employee
Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card