cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
325
Views
5
Helpful
6
Replies

6509 and MLS

gaban
Level 1
Level 1

I just did the command

"set mls flow ip full" on our 6509 as recommended by cisco to check users who are infected by the NAchi worm and using ICMP.

Is there a way to take this out. Would it OK to leave it on.

thanks,

gilbert

1 Accepted Solution

Accepted Solutions

The sup1 uses mls cache to store hw fwd entries. Since the tcam has limited resources you would use the command I gave to determine if you were approaching it's limits - resulting in some traffic being punted up to the msfc for forwarding. This would be a potential problem of running with full flow mask enabled. However, you have sup2 which uses hw based cef for forwarding and not mls. The mls information is still maintain but is used for netflow stats and not hw forwarding so there shouldn't be any performance impact in your case.

View solution in original post

6 Replies 6

tsettle
Level 3
Level 3

Is this a sup1 or sup2? 'sh mls' will tell how many of your sup1 mls entries are used in your cache. If it's not too many then you may be ok with leaving it enabled. Otherwise, 'set mls flow destination' will back you out.

thanks for the quick reply. We have sup2's I am not sure what is "how many" but it is large. Beside ICMP can I try to find other ports with MLS? for example workstation that are using port 135?

Can i use something like this on an IOS based switch

here is the link

http://www.cisco.com/en/US/products/sw/voicesw/ps556/products_tech_note09186a00801b143a.shtml

It has the commands for IOS based swithes.

hope it helps

Figured out how to do it to ge to the 135 ports thanks!

The sup1 uses mls cache to store hw fwd entries. Since the tcam has limited resources you would use the command I gave to determine if you were approaching it's limits - resulting in some traffic being punted up to the msfc for forwarding. This would be a potential problem of running with full flow mask enabled. However, you have sup2 which uses hw based cef for forwarding and not mls. The mls information is still maintain but is used for netflow stats and not hw forwarding so there shouldn't be any performance impact in your case.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: