I have this working and it apears to work. My question is why/how is it working without nbar?
I don't have nbar turned on (and do not whish to) yet it matches protocol ipsec.
This is what I have setup and the goal is;
1. Not drop ipsec traffic from another site (other site cannot send above 2 mbs)
2. Police/drop Internet traffic above 7mbs
Here are the relevent parts of the config
class-map match-any VPN-TRAFFIC match protocol ipsec
policy-map POLICING-INBOUND class VPN-TRAFFIC police cir 2048000 bc 16000 conform-action transmit exceed-action transmit class class-default police cir 7000000 bc 35000 conform-action transmit exceed-action drop
The Author of this posting offers the information contained within this posting without consideration and with the reader's understanding that there's no implied or expressed suitability or fitness for any purpose. Information provided is for informational purposes only and should not be construed as rendering professional advice of any kind. Usage of this posting's information is solely at reader's own risk.
In no event shall Author be liable for any damages whatsoever (including, without limitation, damages for loss of use, data or profit) arising out of the use or inability to use the posting's information even if Author has been advised of the possibility of such damage.
You misunderstand all NBAR features. Your class-map, using match protocol, is using NBAR.
NBAR protcol discovery is an optional feature to tally statistics based on NBAR classification.
Hi everyone, I would like to thank you in advance for any help you can provide a newcomer like myself!
Im studying the 100-105 book by Odom and am currently on the topic of Port security. I purchased a used 2960 and I'm trying to follow a...
While deploying a number of 18xx/2802/3802 model access points (APs), which run AP-COS as their operating platform. It can be observed on some occasions that while many of their access points were able to join the fabric WLC withou...
I am going to design and build an LAN network under a tunnel underground with long distance between the switches.
I will have 2 Catalyst switches and 8 Industrial IE3000, and they will be connected with fiber.
For now I am planning on use Layer-2 s...