Re: A question for the list...

Valdis.Kletnieks_at_vt.edu
Date: 05/23/03

  • Next message: Rob Shein: "RE: Possible Intrusion Attempt?"
    To: Gary Flynn <flynngn@jmu.edu>
    Date: Fri, 23 May 2003 13:50:07 -0400
    

    On Thu, 22 May 2003 16:30:52 EDT, Gary Flynn <flynngn@jmu.edu> said:

    > I'm not sure what to say about the problems with
    > router performance. Other access control implementations
    > could probably be designed to improve the efficiency of
    > this process using (better?) hardware support for the
    > filtering function.

    The more modern Cisco boxes can handle fairly extensive ACLs at line speed,
    and you can optimize it a lot by realizing that 95% or more customer ports
    will have the "default" config and can share an ACL. And the Juniper and Fore
    gear has always done well in that area.

    However, there's a *LOT* of mom-n-pop ISPs out there who are running old
    Cisco boxes they bought on E-Bay ("Networking and Telecom > Routers, switches"
    currently has 12,205 items listed) - and when a 7206 is running $8K, and you
    can pick up a 2610 for $375, the 7206's added CPU to deal with ACL's better
    be able to save you some $7,500 for it to make business sense...

    
    



  • Next message: Rob Shein: "RE: Possible Intrusion Attempt?"