North American Network Operators Group

Date Prev | Date Next | Date Index | Thread Index | Author Index | Historical

Re: DOS?

  • From: Rob Thomas
  • Date: Sat Jan 25 12:21:15 2003

Hi, NANOGers.

] access-list 150 deny udp any any eq 1434 log-input

Be _very_ careful about enabling such logging.  Some of the worm flows
have filled GigE pipes.  I doubt you really want to log that; Netflow
is a better option in this case.  Too much logging will raise the CPU
utilization to the point of creating a DoS on the router.

Thanks,
Rob.
-- 
Rob Thomas
http://www.cymru.com
ASSERT(coffee != empty);




  • Follow-Ups:
  • References: