Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Community Member

Controlling UDP traffic

Is there a way to control the amount of UDP traffic flowing through a router ? I am seeing excessive amounts of UDP traffic going through out internet router , specifically the NAT tables. I suspect some or other P2P app. but these things use dynamic port numbers which make it very dificult to control via ACL.

Can anybody advise ?

1 ACCEPTED SOLUTION

Accepted Solutions
Silver

Re: Controlling UDP traffic

You could use either Committed Access Rate (CAR) or Generic Traffic Shapping (GTS) with an access list to rate limit your UDP traffic

GTS

http://www.cisco.com/univercd/cc/td/doc/product/software/ios122/122cgcr/fqos_c/fqcprt4/qcfgts.htm

CAR

http://www.cisco.com/univercd/cc/td/doc/product/software/ios122/122cgcr/fqos_c/fqcprt1/qcfcar.htm

Alternatively you could use Class Based Weighted Fair Queuing (CBWFQ) and assign an amount of bandwidth to the traffic

http://www.cisco.com/univercd/cc/td/doc/product/software/ios122/122cgcr/fqos_c/fqcprt8/qcfmcli2.htm

4 REPLIES
VIP Purple

Re: Controlling UDP traffic

Hello,

I am thinking you could use an extended access list and specifically allow one UDP port (e.g. NTP), all others would be denied automatically by the implicit deny. Not sure if this works, but maybe worth trying.

Regards,

Georg

Silver

Re: Controlling UDP traffic

You could use either Committed Access Rate (CAR) or Generic Traffic Shapping (GTS) with an access list to rate limit your UDP traffic

GTS

http://www.cisco.com/univercd/cc/td/doc/product/software/ios122/122cgcr/fqos_c/fqcprt4/qcfgts.htm

CAR

http://www.cisco.com/univercd/cc/td/doc/product/software/ios122/122cgcr/fqos_c/fqcprt1/qcfcar.htm

Alternatively you could use Class Based Weighted Fair Queuing (CBWFQ) and assign an amount of bandwidth to the traffic

http://www.cisco.com/univercd/cc/td/doc/product/software/ios122/122cgcr/fqos_c/fqcprt8/qcfmcli2.htm

Community Member

Re: Controlling UDP traffic

This is the conclusion I came to as well but thx for the confirmation.

Re: Controlling UDP traffic

First, you should try to find out what it is. Most protocols use fixed ports to start sessions. Blocking these ports will effectively stop connections.

You might have trouble with Kazaa or something like that.

Kazaa uses port 2340 or 80 as an alternate.

Hope this helps,

Leo

131
Views
0
Helpful
4
Replies
CreatePlease to create content