cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
318
Views
0
Helpful
2
Replies

nbar protocol discovery output and rip

mark.vicuna
Level 1
Level 1

Hi All,

I'm currently using nbar for protocol discovery on a network running

rip. I've noticed that nbar will only discover rip packets inbound on an

interface. The interface(s) used do not have passive interface

set for rip or an access list denying udp 520. I'm currently using this

on 2 different platforms (2610XM and 3660) with 2 different IOS codes

(12.2(8)T4 and 12.2(5)) respectively.

I'm starting to think that this is the norm for nbar.. anyone

experienced the same results?

Cheers,

Mark.

2 Replies 2

bstremp
Level 2
Level 2

I believe NBAR only checks the inbound traffic when used for protocol discovery. Here is a useful URL I found for NBAR:

http://www.cisco.com/warp/public/732/Tech/qos/nbar/

NBAR checks outbound and inbound - there are 2 columns per protocol/port [inbound and outbound]- otherwise there is no use for NBAR to work with QOS if it only does half it's job.

I can see other types of traffic on both inbound and outbound.