From: joshua lauer (jslauer@hotmail.com)
Date: Sun May 08 2005 - 17:41:17 GMT-3
yes,
very correct.
JL
<br><br><br>>From: "ccie2be"
<ccie2be@nyc.rr.com><br>>Reply-To: "ccie2be"
<ccie2be@nyc.rr.com><br>>To: <gladston@br.ibm.com>,
<ccielab@groupstudy.com><br>>CC: "Scott Morris"
<swm@emanon.com>, "Bob Sinclair"
<bsinclair@netmasterclass.net><br>>Subject: RE: Marking DLSW with
NBAR<br>>Date: Sun, 8 May 2005 16:21:42
-0400<br>><br>>Hi,<br>><br>>match protocol dlsw won't match dlsw
when dlsw is configured with tcp or fst<br>>encapsulation. I'm fairly
sure this will only work when either direct or<br>>dlsw lite encap is
used.<br>><br>>I seem to recall Scott Morris or Bob Sinclair pointing
this out on GS.<br>>check the archives.<br>><br>>HTH,
Tim<br>><br>>-----Original Message-----<br>>From:
nobody@groupstudy.com [mailto:nobody@groupstudy.com] On Behalf
Of<br>>gladston@br.ibm.com<br>>Sent: Sunday, May 08, 2005 11:08
AM<br>>To: ccielab@groupstudy.com<br>>Subject: Marking DLSW with
NBAR<br>><br>>R2 is marking telnet and dlsw packets using CB called
from a frame class.<br>>Telnet is marked correctly,<br>>but DLSW is
not.<br>>Do you think match protocol dlsw matches just real dlsw
transport traffic,<br>>and not dlsw session?<br>><br>>dlsw peer
exist between R5 and R3:<br>>Rack2R5>sh tcp brief<br>>TCB
Local Address Foreign Address (state)<br>>8318400C
142.20.5.1.11000 142.20.6.1.179 ESTAB<br>>831AF9A8
142.20.5.1.11001 142.20.3.1.2065 ESTAB<br>>8316F6D0
142.20.125.5.179 142.20.125.1.11001 ESTAB<br>>831D8F4C
142.20.5.1.23 142.20.23.3.11009 ESTAB<br>><br>>R2 is
between R5 and R3<br>><br>><br>>R2
config:<br>><br>><br>>class-map dlsw<br>>match protocol
dlsw<br>>!<br>>class-map telnet<br>>match protocol
telnet<br>>!<br>>class-map match-all voip-rtp<br>>match ip rtp
16384 16383<br>>!<br>>!<br>>policy-map
Priority-with-FRTS<br>>class voip-rtp<br>>priority 32<br>>class
dlsw<br>>set dscp 55<br>>class telnet<br>>set dscp
60<br>>!<br>>interface Serial0/1<br>>ip address 142.20.23.2
255.255.255.0<br>>no sh<br>>ip router isis<br>>encapsulation
frame-relay<br>>no fair-queue<br>>isis circuit-type
level-2-only<br>>isis authentication mode md5 level-2<br>>isis
authentication key-chain Isis-authen level-2<br>>frame-relay class
Frts-to-r3<br>>frame-relay traffic-shaping<br>>frame-relay map clns
200 broadcast<br>>frame-relay map ip 142.20.23.3 200 broadcast<br>>no
frame-relay inverse-arp<br>>!<br>><br>>map-class frame-relay
Frts-to-r3<br>>frame-relay cir 128000<br>>frame-relay bc
1280<br>>frame-relay be 0<br>>frame-relay mincir
64000<br>>frame-relay adaptive-shaping becn<br>>service-policy output
Priority-with-FRTS<br>><br>>Monitoring:<br>>Rack2R2#sh policy-map
interface ser 0/1<br>> Serial0/1: DLCI 200 -<br>><br>>
Service-policy output: Priority-with-FRTS<br>><br>> Class-map:
voip-rtp (match-all)<br>> 0 packets, 0 bytes<br>> 5 minute
offered rate 0 bps, drop rate 0 bps<br>> Match: ip rtp 16384
16383<br>> Queueing<br>> Strict Priority<br>>
Output Queue: Conversation 24<br>> Bandwidth 32 (kbps) Burst 800
(Bytes)<br>> (pkts matched/bytes matched) 0/0<br>>
(total drops/bytes drops) 0/0<br>><br>> Class-map: dlsw
(match-all)<br>> 0 packets, 0 bytes<br>> 5 minute offered
rate 0 bps, drop rate 0 bps<br>> Match: protocol dlsw<br>>
QoS Set<br>> dscp 55<br>> Packets marked
0<br>><br>> Class-map: telnet (match-all)<br>> 28
packets, 1646 bytes<br>> 5 minute offered rate 0 bps, drop rate 0
bps<br>> Match: protocol telnet<br>> QoS Set<br>>
dscp 60<br>> Packets marked 28<br>><br>>
Class-map: class-default (match-any)<br>> 1175 packets, 1127462
bytes<br>> 5 minute offered rate 2000 bps, drop rate 0 bps<br>>
Match: any<br>><br>><br>>Rack2R3(config)#dls
dis<br>>Rack2R3(config)#do sh dls peer<br>>Rack2R3(config)#no dls
dis<br>>Rack2R3(config)#do sh dls peer<br>>Peers: state
pkts_rx pkts_tx type drops ckts TCP<br>>uptime<br>> TCP
142.20.5.1 CONNECT 2 2 conf 0 0
0<br>>00:00:02<br>>Total number of connected peers: 1<br>>Total
number of connections: 1<br>><br>><br>>Rack2R2#sh policy-map
interface ser 0/1<br>> Serial0/1: DLCI 200 -<br>><br>>
Service-policy output: Priority-with-FRTS<br>><br>> Class-map:
voip-rtp (match-all)<br>> 0 packets, 0 bytes<br>> 5 minute
offered rate 0 bps, drop rate 0 bps<br>> Match: ip rtp 16384
16383<br>> Queueing<br>> Strict Priority<br>>
Output Queue: Conversation 24<br>> Bandwidth 32 (kbps) Burst 800
(Bytes)<br>> (pkts matched/bytes matched) 0/0<br>>
(total drops/bytes drops) 0/0<br>><br>> Class-map: dlsw
(match-all)<br>> 0 packets, 0 bytes<br>> 5 minute offered
rate 0 bps, drop rate 0 bps<br>> Match: protocol dlsw<br>>
QoS Set<br>> dscp 55<br>> Packets marked
0<br>><br>> Class-map: telnet (match-all)<br>> 36
packets, 2010 bytes<br>> 5 minute offered rate 0 bps, drop rate 0
bps<br>> Match: protocol
telnet<br>><br>>_______________________________________________________________________<br>>Subscription
information may be found
at:<br>>http://www.groupstudy.com/list/CCIELab.html
>><br>>_______________________________________________________________________<br>>Subscription
information may be found
at:<br>>http://www.groupstudy.com/list/CCIELab.html
>
This archive was generated by hypermail 2.1.4 : Fri Jun 03 2005 - 10:11:57 GMT-3