cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
236
Views
0
Helpful
1
Replies

Router's IDS performance

ovt
Level 4
Level 4

Hi all!

How does router's IDS affect router performance? In the output of "show ip

audit stat" I see that many signatures are handled in the process switching

mode, for example: 1004 (LSRR, SSRR), 2000 (echo replay !?), 2150

(fragmented ICMP), TCP scans, etc. Is that ok?

Thanks,

Oleg Tipisov,

REDCENTER,

Moscow

1 Reply 1

gfullage
Cisco Employee
Cisco Employee

Turning on IDS affects a routers performance greatly. I would NOT do this on a busy router, use an IDS sensor for that purpose if you're really serious about IDS. Since the router has to look at all parts of the packet, not just the header, a lot of the traffic is then process switched. Plus the router only looks for a small subset of all the signatures that a sensor will capture.