2003, Cisco Systems, Inc. All rights reserved.



Similar documents
Network-Based Application Recognition

Lab 3.3 Configuring QoS with SDM

- QoS Classification and Marking -

Application Aware Traffic Engineering and Monitoring

Implementing Cisco Quality of Service QOS v2.5; 5 days, Instructor-led

Using IPM to Measure Network Performance

QoS: Color-Aware Policer

Lab QoS Classification and Policing Using CAR

All You Ever Wanted to Know About Network Management in 90 Minutes. (More or Less)

Optimizing Converged Cisco Networks (ONT)

"Charting the Course to Your Success!" QOS - Implementing Cisco Quality of Service 2.5 Course Summary

The Power of SA as a SLM Tool

Routing. Static Routing. Fairness. Adaptive Routing. Shortest Path First. Flooding, Flow routing. Distance Vector

IMPLEMENTING CISCO QUALITY OF SERVICE V2.5 (QOS)

Monitoring and analyzing audio, video, and multimedia traffic on the network

Configuring Control Plane Policing

Flow Monitor for WhatsUp Gold v16.2 User Guide

- QoS and Queuing - Queuing Overview

WhatsUpGold. v14.4. Flow Monitor User Guide

Description: To participate in the hands-on labs in this class, you need to bring a laptop computer with the following:

IBM. Tivoli. Netcool Performance Manager. Cisco Class-Based QoS Technology Pack. User Guide. Document Revision R2E1

How To Lower Data Rate On A Network On A 2Ghz Network On An Ipnet 2 (Net 2) On A Pnet 2 On A Router On A Gbnet 2.5 (Net 1) On An Uniden Network On

Cisco Performance Monitor Commands

IP SLAs Overview. Finding Feature Information. Information About IP SLAs. IP SLAs Technology Overview

Chapter 4 Rate Limiting

Flow Monitor for WhatsUp Gold v16.1 User Guide

Configuring Denial of Service Protection

Quality of Service Commands

Table of Contents. Cisco Blocking Peer to Peer File Sharing Programs with the PIX Firewall

DS3 Performance Scaling on ISRs

WhatsUpGold. v15.0. Flow Monitor User Guide

Configuring MPLS QoS

Policing and Shaping Overview

Network Monitoring Using Cisco Service Assurance Agent

PC-over-IP Protocol Virtual Desktop Network Design Checklist. TER Issue 2

The Basics. Configuring Campus Switches to Support Voice

Network Performance Monitoring at Minimal Capex

Cisco PIX. Upgrade-Workshop PixOS 7. Dipl.-Ing. Karsten Iwen CCIE #14602 (Seccurity)

Cisco ASA, PIX, and FWSM Firewall Handbook

Configuring Class Maps and Policy Maps

This topic lists the key mechanisms use to implement QoS in an IP network.

AutoQoS for Medianet

Introduction to Network Address Translation

CiscoWorks Internetwork Performance Monitor

How To Configure Qos On A Network With A Network (Cisco) On A Cell Phone Or Ipad On A Pq-Wifi On A 2G Network On A Cheap Cell Phone On A Slow Network On An Ipad Or Ip

How To Configure Voip Qos For A Network Connection

Optimizing Converged Cisco Networks (ONT)

Configuring QoS in a Wireless Environment

DEPLOYING QUALITY OF SERVICE FOR CONVERGED NETWORKS

Highlighting a Direction

Deploying ACLs to Manage Network Security

Chapter 2 Quality of Service (QoS)

About Firewall Protection

The Ecosystem of Computer Networks. Ripe 46 Amsterdam, The Netherlands

Network Worm/DoS. System Engineer. Cisco Systems Korea

Configuring Quality of Service

Configuring Quality of Service

Load Balance Router R258V

ILTA HAND 8 QoS/CoS. Agenda. What is it?

Class of Service Data Collection Document. For AT&T Managed Internet Service (MIS)

Basic Network Configuration

Cisco Quality of Service and DDOS

Enabling Remote Access to the ACE

Application Note. Configuring WAN Quality of Service for ShoreTel. Quality of Service Overview. Quality of Service Mechanisms. WAN QoS for ShoreTel 5

Chapter 3 Using Maintenance & Troubleshooting Tools & Applications Objectives

IOS NAT Load Balancing with Optimized Edge Routing for Two Internet Connections

Authentication with 802.1x and EAP Across Congested WAN Links

Securing Networks with PIX and ASA

CISCO IOS IP SERVICE LEVEL AGREEMENT

A host-based firewall can be used in addition to a network-based firewall to provide multiple layers of protection.

Output Interpreter. SHOW RUNNING-CONFIG SECURITY Analysis SHOW RUNNING-CONFIG - FW Analysis. Back to top

Get Application Aware with Your Cisco Network Devices

Quality of Service (QoS)) in IP networks

Improving Quality of Service

Cisco IOS Quality of Service Solutions Command Reference. Release 12.2 T

Ethernet Overhead Accounting

Best Practice Recommendations for VLANs and QoS with ShoreTel

This topic describes the basic purpose and function of AutoQoS. One command per interface to enable and configure QoS

Configuring NetFlow Secure Event Logging (NSEL)

02-QOS-ADVANCED-DIFFSRV

Configuring QoS and Per Port Per VLAN QoS

Cisco IOS Flexible NetFlow Technology

Quality of Service (QoS) for Enterprise Networks. Learn How to Configure QoS on Cisco Routers. Share:

Lab Analyzing Network Traffic

EXPLORER. TFT Filter CONFIGURATION

Internet Protocol: IP packet headers. vendredi 18 octobre 13

Quality of Service Analysis of site to site for IPSec VPNs for realtime multimedia traffic.

CiscoWorks Internetwork Performance Monitor 4.0

Internetwork Expert s CCNA Security Bootcamp. IOS Firewall Feature Set. Firewall Design Overview

Configuring QoS in a Wireless Environment

Task 20.1: Configure ASBR1 Serial 0/2 to prevent DoS attacks to ASBR1 from SP1.

PCoIP Protocol Network Design Checklist. TER Issue 3

Sup720 Hardware Assisted Features

QoS Design and Validation for Enterprise Networks

APPLICATION NOTE 209 QUALITY OF SERVICE: KEY CONCEPTS AND TESTING NEEDS. Quality of Service Drivers. Why Test Quality of Service?

Lab Configure Cisco IOS Firewall CBAC on a Cisco Router

AnyWeb AG / ITSM Practice Circle / Christof Madöry

Common Application Guide

Approach to build MPLS VPN using QoS capabilities

Configuring Server Load Balancing

Transcription:

2003, Cisco Systems, Inc. All rights reserved. 1

Transparenz und Kontrolle von Netzwerkapplikationen Roland Schön Internetworking Consultant CCIE # 1785 Public Sector Team, Cisco Germany rschoen@cisco.com 2003, Cisco Systems, Inc. All rights reserved. 2

Agenda Erkennung von Netzwerkapplikationen - NBAR Funktion im IOS Einschränkung von Bandbreiten - NBAR und Policing - Rate-Limiting (Benutzer-basiert) SAA Service Assurance Agent G-WiN Zugangsrouter

Stimmt die Aussage...? There is always enough bandwidth available in my network and on my Internet-Connection. For each and every application! The Network Admin 2003, Cisco Systems, Inc. All rights reserved. 4

NBAR Übersicht Intelligent Classification Engine in Cisco IOS Used in conjunction with QoS class-based features Protocol Discovery analyzes application traffic patterns in real time Discovers which traffic is running on the network Supported Platforms Cisco 1700 Cisco 2600 Cisco 3600 / 3700 Cisco 7100 / 7200 Cisco 7500 Catalyst 6500 Flex Wan 2003, Cisco Systems, Inc. All rights reserved. 5

Network Based Application Recognition (NBAR) My application is too slow! Protect your business critical traffic / applications Router Link-Utilization Citrix 25% Netshow 15% Gnutella 10% FTP 30% HTTP 20% Citrix Action: Mark Citrix real-time as GOLD service and police FTP. Block Gnutella Result: Guarantee bandwidth for Citrix! 2003, Cisco Systems, Inc. All rights reserved. 6

Intelligente Klassifizierung von IP-Paketen IP Packet Classification Engine capable of classifying Applications that have Statically assigned TCP and UDP port numbers Non-TCP and Non-UDP IP protocols Dynamically assigned TCP and UDP port numbers during connection establishment Sub-port classification or Classification based on deep inspection Ability to look deeper into the packet to identify applications. HTTP traffic by URL, host name or MIME type using regular expressions (*,?, [ ]), Citrix ICA traffic, RTP Payload type classification NBAR Currently Supports >85 protocols/applications 2003, Cisco Systems, Inc. All rights reserved. 7

Das Inspizieren von IP Paketen IP Packet Stateful/Dynamic Inspection TCP/UDP Packet Data Packet ToS Byte Source IP Addr Dest IP Addr Src Port Dst Port Sub-Port/Deep Inspection egp exchange kerberos secure-nntp smtp gre finger l2tp notes snmp icmp ftp ldap novadigm socks ipinip secure-ftp secure-ldap ntp sqlnet ipsec gopher netshow pcanywhere ssh eigrp http pptp pop3 streamwork bgp secure-http sqlserver secure-pop3 syslog cuseeme imap netbios printer telnet dhcp irc nfs realaudio secure-telent dns secure-irc nntp rcmd tftp fasttrack gnutella citrix napster vdolive xwindows http://www.cisco.com/univercd/cc/td/doc/product/software/ios122/122newft/122t/122t8/dtnbarad.htm 2003, Cisco Systems, Inc. All rights reserved. 8

Wie werden NBAR neue Applikationen hinzugefügt? Through the use of PDLM: Packet Description Language Module Custom-xx functionality in NBAR for Static TCP/UDP port applications 2003, Cisco Systems, Inc. All rights reserved. 9

Packet Description Language Module PDLMs define applications recognizable by NBAR New applications easily supported by adding new PDLMs No Cisco IOS software upgrade or reboot required to add new PDLMs* PDLMs must be produced by Cisco engineers * in most cases 2003, Cisco Systems, Inc. All rights reserved. 10

Custom-xx NBAR Funktion Used for static TCP/UDP port based applications that are not supported in NBAR. Up to 10 custom applications can be added Map 16 TCP and UDP ports each per application Statistics appear in the Protocol Discovery Router(config)#ip nbar port-map custom-01? - tcp TCP ports - udp UDP ports 2003, Cisco Systems, Inc. All rights reserved. 11

Protocol Discovery The Protocol Discovery feature discovers and provides real time statistics on applications per-interface, per-protocol, bi-directional statistics: 5 minute bit rate (bps) packet counts and byte counts. 2003, Cisco Systems, Inc. All rights reserved. 12

NBAR Protocol Discovery + QDM Graph Router# show ip nbar protocol-discovery interface FastEthernet 6/0 FastEthernet6/0 Input Output Protocol Packet Count Packet Count Byte Count Byte Count 5 minute bit rate (bps) 5 minute bit rate (bps) ------------------------ ------------------------ ------------------------ http 316773 0 26340105 0 3000 0 pop3 4437 7367 2301891 339213 3000 0 snmp 279538 14644 319106191 673624 0 0 ftp 8979 7714 906550 694260 0 0 Total 17203819 151684936 19161397327 50967034611 4179000 6620000 2003, Cisco Systems, Inc. All rights reserved. 13

Kürzliche NBAR Erweiterungen Addition of New Applications and Protocols - Fasttrack & Gnutella PDLM on CCO Next Generation of Napster (aquired by Roxio) like applications Peer 2 Peer file sharing applications KaZaa, Morpheus, Grokster and Gnutella Does not require an IOS Release upgrade - Real-Time Protocol Payload (RTP) Classification [ since 12.2(8)T and 12.1(11b)E ] Stateful mechanism to identify real time audio and video traffic Differentiate on the basis of audio and video codecs 2003, Cisco Systems, Inc. All rights reserved. 14

Peer-to-Peer File Sharing Fasttrack: Kazaa, Morpheus, Grokster, Imesh clients Concept of Super Nodes: Simplifies the search criteria Currently Supported in NBAR as: Match protocol fasttrack file-transfer * Match protocol fasttrack file-transfer *.mpeg 2003, Cisco Systems, Inc. All rights reserved. 15

Peer-to-Peer File Sharing Gnutella: BearShare, LimeWire, Gnotella Currently Supported in NBAR as: Match protocol gnutella file-transfer * Match protocol gnutella file-transfer *.mpeg 2003, Cisco Systems, Inc. All rights reserved. 16

Agenda Erkennung von Netzwerkapplikationen - NBAR Funktion im IOS Einschränkung von Bandbreiten - NBAR und Policing - Rate-Limiting (Benutzer-basiert) SAA Service Assurance Agent G-WiN Zugangsrouter

Konfiguration u. Auswertung von NBAR 2003, Cisco Systems, Inc. All rights reserved. 18

1. Enable NBAR + Protocol discovery Router(config)# interface FastEthernet 1/0 ip nbar protocol-discovery Router# sh ip nbar protocol-discovery interface FastEthernet 1/0 Input Output Protocol Packet Count Packet Count Byte Count Byte Count 5 minute bit rate (bps) 5 minute bit rate (bps) ------------------------ ------------------------ ------------------------ http 316773 0 26340105 0 3000 0 pop3 4437 7367 2301891 339213 3000 0 2003, Cisco Systems, Inc. All rights reserved. 19

1. Beispiel Protokoll Erkennung Router# sh ip nbar protocol-discovery interface Pos 4/0/0 Input Output Protocol Packet Count Packet Count Byte Count Byte Count 30 second bit rate (bps) 30 second bit rate (bps) ------------------------ ------------------------ ------------------------ http 404027 200244 273232074 37517508 10991000 1619000 napster 177077 58502 114679726 13561639 4471000 649000 fasttrack 60351 33114 49621236 27391991 2431000 905000 smtp 17451 9569 2067432 11833858 50000 428000 secure-http 20126 8657 13451947 1097178 364000 40000 4,5Mbit/s 2,5Mbit/s 2003, Cisco Systems, Inc. All rights reserved. 20

2. Create Class Map Classification which traffic to look at? class-map match-all peer2peer match protocol gnutella file-transfer * match protocol fasttrack file-transfer *.mpeg match protocol kazaa2 class-map match-all sports match acl 103 match protocol url *sports* 2003, Cisco Systems, Inc. All rights reserved. 21

3. Create Policy Map Policing What to do with classified packets? e.g. drop policy-map Limit-fileshare class-map peer2peer police 1000000 conform-action transmit exceed-action drop class-map sports police Limit to 1 Mbit/s, all above will be dropped 2003, Cisco Systems, Inc. All rights reserved. 22

4. Create Service Map Apply to an interface (for example FE 1/0) Router(config)# interface FastEthernet 1/0 service-map input limit-fileshare service-map output limit-fileshare 2003, Cisco Systems, Inc. All rights reserved. 23

5. Optional: Load PDLM PDLM Packed Description Language Module Add Protocol for NBAR Classification Engine with out IOS Update Router(config)# ip nbar pdlm <flash location> fasttrack.pdlm PDLMs can be found on CCO: http://www.cisco.com/cgi-bin/tablebuild.pl/pdlm 2003, Cisco Systems, Inc. All rights reserved. 24

6. NBAR zum Klassifizieren von P2P Appl. und deren Einstufung in Best-Effort Klasse Activate PDLM into RAM: ip nbar pdlm flash:gnutella.pdlm Use MQC match protocol statements to classify the traffic class-map match-any protocol P2P match protocol gnutella match protocol fasttrack (identifies KaZaa, Morpheus and Grokster) WRED DSCP Based to cause drops from this traffic first policy-map P2P class P2P set dscp 2 Alternative is to place in separate bandwidth based queue with very small bandwidth guarantee policy-map P2P class P2P set dscp 2 policy-map QoS-Policy class class-default fair-queue random-detect dscp-based policy-map P2P-CBWFQ-MIN class P2P bandwidth percent 1 2003, Cisco Systems, Inc. All rights reserved. 25

Refresher: Mechanismus des Policing Policy required: Make sure my traffic does not get more than x kbps of bandwidth at any time 2003, Cisco Systems, Inc. All rights reserved. 26

Policing vs. Shaping Traffic Traffic Traffic Rate Time Traffic Rate Time Policing Shaping Traffic Traffic Traffic Rate Time Traffic Rate Time Policer Causes TCP resends Oscillation of TCP windows Ingress Rate limiting with No buffering (drop) Shaper Egress Rate limiting with Buffering (delay or drop) Can adapt to network congestion (FR BECN, FECN) 2003, Cisco Systems, Inc. All rights reserved. 27

Traffic Shaping und Policing Implementierungen Shaping mechanisms: Class-based shaping Frame Relay traffic shaping (FRTS) Generic traffic shaping (GTS) Policing mechanisms: Two rate policer Class-based policing Committed access rate (CAR) 2003, Cisco Systems, Inc. All rights reserved. 28

Class-based Policer (1) Single Rate Policer Bc = Burst Commited Bc = CIR * Tc Bc + Be Bc Packet of Size B B < Bc+Be Be Yes No Conform Exceed Action Action 2003, Cisco Systems, Inc. All rights reserved. 29

Class-based policer (2) RFC 2698: Two Rate Three Color Policer in 12.2T Be = Burst Excess Be = PIR * Te Bc = Burst Commited Bc = CIR * Tc B > Be(t) No B > Bc(t) No Packet of Size B Yes Yes Violate Exceed Conform Drop Action Action 2003, Cisco Systems, Inc. All rights reserved. 30

Agenda Erkennung von Netzwerkapplikationen - NBAR Funktion im IOS Einschränkung von Bandbreiten - NBAR und Policing - Rate-Limiting (Benutzer-basiert) SAA Service Assurance Agent G-WiN Zugangsrouter

Zukünftiges Feature im Cat6K User-Based Rate Limiting z.b. Studentenwohnheim Traffic from Dorms Ingress Microflow policer Applied to user ports(s) Source-only Flow mask Use ACL to limit the scope of source IP addresses to intended users Traffic from Internet Ingress Microflow policer Applied to uplink ports Dest-only Flow mask Use ACL to limit the scope of destination IP addresses to intended users 2003, Cisco Systems, Inc. All rights reserved. 32

Zukünftiges Feature im Cat6K User-Based Rate Limiting - Konfiguration User Subnets 10.10.n.x/24 int fast4/1-48 int gig3/1 Internet Traffic from Dorms access-list 101 permit ip 10.10.n.0 0.0.0.255 any class-map Users-Outbound match access-group 101 policy-map Users-Outbound class Users-Outbound police flow mask src-only blah int range fast4/1-48 service-policy input Users-Outbound Traffic from Internet access-list 102 permit ip any 10.10.n.0 0.0.0.255 class-map Users-Inbound match access-group 102 policy-map Users Inbound class Users-Inbound police flow mask dest-only blah ** int gig 3/1 service-policy input Users-Inbound ** e.g.: police flow mask dest-only 128000 1000 conform-action transmit exceed-action drop Scales to 64 Different Rates and 128K Host IP addresses 2003, Cisco Systems, Inc. All rights reserved. 33

More Information on NBAR Main QoS Page http://www.cisco.com/go/qos Main NBAR Page http://www.cisco.com/warp/public/732/tech/qos/nbar/ NBAR Docs: http://www.cisco.com/univercd/cc/td/doc/product/software/ios122/ 122newft/122t/122t8/dtnbarad.htm 2003, Cisco Systems, Inc. All rights reserved. 34

Agenda Erkennung von Netzwerkapplikationen - NBAR Funktion im IOS Einschränkung von Bandbreiten - NBAR und Policing - Rate-Limiting (Benutzer-basiert) SAA Service Assurance Agent G-WiN Zugangsrouter

Service-Level Monitoring im Netz Monitoren von SLAs Cisco IOS Router mit SA Agent SA Agent Cisco IOS Router mit SA Agent SA Agent Network Core Messbare SLA Metriken sind z.b. Antwortzeit Verfügbarkeit Verletzungen von Schwellwerten Jitter Paketverlust 2003, Cisco Systems, Inc. All rights reserved. 36

Einsatz des SA Agent What s up in my net? Performance Management: Collection, utilization, and performance data; analyze data and set utilization thresholds Why is Performance Management important? Problem isolation Service differentiation Network planning 2003, Cisco Systems, Inc. All rights reserved. 37

SA Agent Funktionsvielfalt Increasing Service Value HTTP FTP Connect DLSw QoS Support (ToS) TCP Jitter DNS/ DHCP UDP Echo SNA Path Echo ICMP Cisco IOS-Based Service Assurance* Agent Echo Path Jitter *With Cisco IOS 12.2(13)T (APM) ATM* Frame Relay MPLS VPN Aware 2003, Cisco Systems, Inc. All rights reserved. 38

IOS Releases und unterstützte Features Feature/Release ICMP Ping ICMP Echo Path SSCP (SNA) UDP Echo TCP Connect UDP Jitter HTTP DNS DHCP DLSw+ One-Way Latency with UDP Jitter FTP Get SNMP Support MPLS VPN Aware Frame Relay (CLI Only) ICMP Path Jitter Application Performance Monitor 11.2 12.0 (3)T 12.0(5)T 12.0(8)S 12.1(1)T 12.2(2)T X X X X X X X X X X X X X X X X X X X X X X X X X X X X X X X X X X X X X X X X X X X X X X X X 2003, Cisco Systems, Inc. All rights reserved. 39

Service Assurance Agent im Betrieb 2003, Cisco Systems, Inc. All rights reserved. 40

Wie funktioniert das mit dem SAA? Hop-by-hop analysis Proactive notification Rising and falling thresholds Robust threshold definition for SLAs SNMP traps generated when SLA violated Thresholds can trigger SA operation activation for further analysis Any IP Host Measure Measure Management Application SNMP Trap Configure Collect Present SA Agent Measure SA Agent Cisco IOS Device Measure (SA Agent Responder) 2003, Cisco Systems, Inc. All rights reserved. 41

SAA Basics Response Source Cisco-RTTMON P1 Response Stats P2 Response Stats P1 P2 Response Destination SNMP Get 2003, Cisco Systems, Inc. All rights reserved. 42

Beispiel 1: ICMP Probe SA Agent Network Any IP Device Does not require SA Agent responder Supports Echo, Path Echo and Path Jitter operations 2003, Cisco Systems, Inc. All rights reserved. 43

Beispiel 1: Echo IP SAA Cisco-RTTMon Completions Errors (7 Types) IP ICMP Echo Probe } SumCompletionTime MaxCompletionTime MinCompletionTime } Response IP Core Availability = IP Device a.b.c.d Completions Completions + Errors of IP Network 7 Types of Errors: Disconnects, Timeouts, Busies, No Connections, Drops, Sequence Errors, VerifyErrors 2003, Cisco Systems, Inc. All rights reserved. 44

Beipiel 2: HTTP Probe SAA Cisco-RTTMon HTTP Probe } IP Core HTTPCompletions HTTPErrors Availability = Completions Completions + HTTP Server Errors DNSRTT TCPConnectRTT TransactionRTT RTT to Perform Domain Lookup RTT to Perform TCP Connect to HTTP Server RTT to Send out Request and Get Response from Server 2003, Cisco Systems, Inc. All rights reserved. 45

Configuration Process Set operation number Configure operation type Configure operation characteristics Set reaction conditions Schedule the operation time 2003, Cisco Systems, Inc. All rights reserved. 46

Konfiguration des Operation Type einige Beispiele (config)# rtr 1 Operation number (config-rtr)# type jitter dest-ip a.b.c.d dest-port 99 num-packets 20 interval 20 type http Operation get url http://www.cisco.com type echo protocol ipicmpecho Operation a.b.c.d type tcpconnect dest-ipaddr a.b.c.d dest-port 23 2003, Cisco Systems, Inc. All rights reserved. 47

SA Agent Ecosystem Partner 2003, Cisco Systems, Inc. All rights reserved. 48

Management Applications Supporting SA Agent Internetwork Performance Monitor (IPM) Service Management Suite (SMS) VPN SC CNS Performance Engine ehealth VistaView PowerView Firehunter UpTime IPInsight MRTG Brixworx and Many More 2003, Cisco Systems, Inc. All rights reserved. 49

SA Agent Performance 2003, Cisco Systems, Inc. All rights reserved. 50

SA Agent Performance Memory and CPU usage on a c2600(40mhz M860 CPU): Type UDP Echo Jitter (UDP Plus) ICMP Echo Responder (UDP Echo) Responder (Jitter) # of Source Probe Operations per Minute 2000 1440 2000 3900 1440 Average Memory Usage (Bytes) 13K per Probe 17K per Probe 11K per Probe 58K Total 97K Total Avg. CPU Usage per Probe Operation (msec) 8.65 22.63 1.90 7.60 21.47 CPU usage can be scaled based on the clock frequency of the RISC CPU: 7200(150MHz->40/150=0.27 times) 2003, Cisco Systems, Inc. All rights reserved. 51

Agenda Erkennung von Netzwerkapplikationen - NBAR Funktion im IOS Einschränkung von Bandbreiten - NBAR und Policing - Rate-Limiting (Benutzer-basiert) SAA Service Assurance Agent G-WiN Zugangsrouter

Geräteklassen für G-WiN Zugang und deren NBAR-Support ü NBAR Support Cisco 7200/7500 Medium ü in 12.2S with NPE-G100 Cisco 7300 System Performance 2003, Cisco Systems, Inc. All rights reserved. ü No! Cisco 7600 & Catalyst6500 Cisco 12000 very high 53

NBAR Performance-Zahlen NBAR is CEF supported! No NBAR in PXF-based Systems Performance Impact? Sample1: For Cisco 7200/NPE300, 45 Mbit/s in both directions + 8 % CPU Load for Protocol discovery + 15 % CPU Load for NBAR Classification Sample2: For Cisco 7500 with VIP2-50 to VIP4-80 (dnbar) + approx. 5% performance degradation 2003, Cisco Systems, Inc. All rights reserved. 54

Plattform-Support für SA Agent MC3810 Catalyst Cisco 36xx 4K/5K/6K/ with L3 Mod Cisco 25xx/26xx Cisco AS5400/5800 Cat5K Cisco3700 Cisco 4500/4700 Cisco GSR, 10K Cisco 6400/ 7200/7500, 7300/7400 Cisco 800/100x/14xx/16xx/17xx 2003, Cisco Systems, Inc. All rights reserved. 55

2002, Cisco Systems, Inc. All rights reserved. 57

Backup-slide configuring NBAR! Router config with NBAR enabbled for limiting NAPSTER! ip cef ip nbar pdlm slot0:napster.pdlm!! class-map match-all napster_nonstd match protocol napster non-std class-map match-all napster match protocol napster!! policy-map napout class napster_nonstd police 10000 2500 2500 conform-action drop exceed-action drop class napster police 1000000 250000 250000 conform-action transmit exceed-action drop policy-map napin class napster_nonstd police 10000 2500 2500 conform-action drop exceed-action drop class napster police 3000000 250000 250000 conform-action transmit exceed-action drop! interface FastEthernet0/0 description ***Residence Halls*** ip address xxx.xxx.xxx.xxx 255.255.xxx.xxx no ip mroute-cache duplex full service-policy input napin service-policy output napout atm pvc 5 0 385 aal5snap 30000 30000 2003, Cisco Systems, Inc. All rights reserved. 58! interface FastEthernet0/1 description ***Admin*** ip address xxx.xxx.xxx.xxx 255.255.xxx.xxx ip nbar protocol-discovery duplex full no ip mroute-cache! interface ATM1/0 description *** PVC to Sunnyville CSU router no ip address no atm ilmi-keepalive! interface ATM1/0.1 point-to-point bandwidth 30000 ip address xxx.xxx.xxx.xxx 255.255.xxx.xxx ip nbar protocol-discovery ip policy route-map papapix