cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
511
Views
0
Helpful
3
Replies

Shunning router ACL leaking?

bbenton
Level 1
Level 1

Is it possible that a shunning router will leak normally blocked inbound packets? Possibly when the acl numbers are changed on the inbound shunning interface? We're seeing a few packets get through that should be blocked by the pre-shun acl, and were blocked 100% before shunning was enabled. We've confirmed the pre and post shun are correctly in the active shunning acl.

If it can't happen, where should I be looking for the problem?

Considering also applying the pre-shun to opposite interface outbound for a workaround?

3 Replies 3

dlac455
Level 1
Level 1

A related question is: what happens when the cpu hits 100%? Does that affect how the ACL's are handled?

bbenton
Level 1
Level 1

Good point. Ours is a 3540 is does peak at 100% briefly now rather than the 50% is was peaking at before shunning.

Can anyone shed some light on these things?

bbenton
Level 1
Level 1

Correction, router is 3640.

Anyone else, please?