Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
ovt Bronze
Bronze

Router's IDS performance

Hi all!

How does router's IDS affect router performance? In the output of "show ip

audit stat" I see that many signatures are handled in the process switching

mode, for example: 1004 (LSRR, SSRR), 2000 (echo replay !?), 2150

(fragmented ICMP), TCP scans, etc. Is that ok?

Thanks,

Oleg Tipisov,

REDCENTER,

Moscow

1 REPLY
Cisco Employee

Re: Router's IDS performance

Turning on IDS affects a routers performance greatly. I would NOT do this on a busy router, use an IDS sensor for that purpose if you're really serious about IDS. Since the router has to look at all parts of the packet, not just the header, a lot of the traffic is then process switched. Plus the router only looks for a small subset of all the signatures that a sensor will capture.

95
Views
0
Helpful
1
Replies
CreatePlease to create content