Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Equipment Support » Hardware By Brand » Cisco » [Info] Inspection & performance
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
[CCNA] What would be the best lab? »
« Cisco 878  
AuthorAll Replies

aryoba
Premium,MVM
join:2002-08-22

reply to Sailing_Nut
Re: [Info] Inspection & performance

Is there any other ip inspect command applied anywhere? I know some people apply ip inspect command on multiple interfaces or on the same interface with "in" and "out" simultaneously.

How about any ACL applied to any interface? If there is ACL on any interface, then it should match with the respective ip inspect command. When they don't match, then there will be performance issue on certain or all applications.

As how useful there are, it depends on how you configure the CBAC security as a whole. When you configure them properly, then you will have some decent security on your servers and the rest of machines within your network seamlessly without affecting performance.

Sailing_Nut

join:2006-11-07
Annapolis, MD

I have cleaned tings up in my router but if anything I seem to be experiencing reduced performance.

Si, I guess the best thing would be for me to post my entire config. and hope some of the smart folks here can spot a problem.



rolande
Certifiable
Premium,Mod
join:2002-05-24
Powell, OH
clubs:

Host:
Linksys
AT&T Midwest
Nothing jumps out at me as a glaring issue with your config. What version and feature set of 12.4 IOS are you running? 12.4 is known to have lots of "issues". I personally downgraded one of my own routers to mainline 12.3 to avoid the pain and suffering. I wouldn't call 12.4 anywhere near prime time for deployment. It shouldn't ever hurt to play with new code at home, but in my case it did.

Sailing_Nut

join:2006-11-07
Annapolis, MD

I'm running 12.4(15)T1 on my router.

I'm stretching my memory a bit, but I think I needed to step up to this version because of a feature I'm using, but I can't 100% remember. Either that or the Cisco people tol me I needed to move up to it to solve a problem I was seeing.

aryoba
Premium,MVM
join:2002-08-22
I recall sometime ago you had problem with your DNS server. I don't see the DNS-server-related router configuration anywhere. Therefore I'm not sure if you solve the DNS issue or not.

Sailing_Nut

join:2006-11-07
Annapolis, MD

WOW! You have a way better memory than I do!

I think I might be having some DNS problems now. (I'll go back and look for the solution.)

I do know that I'm having lots of problems with web traffic. A while ago I opened a ticket with Cisco & sent them Wire Shark captures. They said it was a problem with my using inspection and that my ISP (Verizon FiOS)was sending lots of out of order packets and that was causing the inspection to puke.

aryoba
Premium,MVM
join:2002-08-22

Without looking at your traffic inspection packet capture, I'm thinking that you may need to punch in line on your ACL 107 and set static PAT for your DNS server performance just like you set one for your FTP server. A lot of time such setup solves a lot of problem.

Btw, what was the web traffic issue anyway?

Sailing_Nut

join:2006-11-07
Annapolis, MD

Hmmmmm. I didn't think I would need an entry since my DNS server is only a private one and does not have any DNS "duties" that are inbound from the Internet.

My web issues are that sites load slowly or not at all. If a site doesn't load if I refresh in IE it will load very quickly. Sometimes it takes several tries of refreshing to get a site to load.

One other question I just came up with in looking over my config is that I have "ip domain name wtbhome.net" This is not really a public domain name, it is just what I use internally on my network. Could this cause problems?
Forums » Equipment Support » Hardware By Brand » Cisco[CCNA] What would be the best lab? »
« Cisco 878  


Tuesday, 02-Dec 20:43:57 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 9 years online! © 1999-2008 dslreports.com.
page compression OFF
Most commented news this week
· [111] AT&T Metered Billing Trial Hits Second Market
· [86] UDP BitTorrent Will Destroy The Interwebs!
· [72] EFF Challenges Telecom Immunity
· [60] Comcast Tries To Slow Verizon's Philly Entry
· [36] Cablevision Bumps HD Count To 68
· [32] Verizon Tops Consumer Reports Wireless Satisfaction Ratings
· [27] Mega-ISPs, Consumer Advocates Demand Broadband Plan
· [26] Hawaii Telecom Files For Bankruptcy
· [26] T-Mobile Invisible Caps Return
· [26] Comcast To Offer Bandwidth Use Tracker In January
Most people now reading
· [Rant] Bestbuy receipt checker [Rants, Raves, & Praise]
· Is this a good thing for the net? [news,99366]
· Coalition Government Possible? [TekSavvy]
· Level 80 PVP gear info? [World of Warcraft]
· [WotLK] Starting the Rep Grind [World of Warcraft]
· It's official ... Macs need anti-virus software [Security]
· Notice, new uTorrent Alpha may be able to evade throttling [TekSavvy]
· [WotLK] New Hunter Macros [World of Warcraft]
· New massive botnet being built with latest Windows exploit [Security]