Re: TFTP QOS with NBAR

From: John (jgarrison1@austin.rr.com)
Date: Wed Oct 17 2007 - 23:41:12 ART


I'm running c3725-adventerprisek9-mz.124-16 and when I used NBAR to classify
the traffic and put it in a high priority queue it put the traffic into the
default queue. I changed the command to telnet and it worked just fine.
  ----- Original Message -----
  From: Joel Amao
  To: John
  Cc: ccielab@groupstudy.com
  Sent: Wednesday, October 17, 2007 6:13 PM
  Subject: RE: TFTP QOS with NBAR

  I am not too sure but i think this has beed fixed in newer codes.

   I ran into this issue in the past, where NBAR would classify tftp packets
as unknown because after the initial setup on a standard port (port 69), the
server replies to the client to setup the connection on a random transfer
identifier (TID).
  The problem is that this TID is passed down to the datagram layer and used
as the port number (random ports number) thus confusing Nbar.

  I havent tested this recently though.

  regards,

  Joel Amao
  CCIE#18128

  <
>

> From: jgarrison1@austin.rr.com
> To: ccielab@groupstudy.com
> Subject: TFTP QOS with NBAR
> Date: Wed, 17 Oct 2007 14:35:26 -0600
>
> TFTP only uses port 69 in it's initial packet. Does NBAR montior a rnage
of
> ports or just port 69. If it doesn't monitor other ports how does it know
to
> distinguish TFTP packets with ports other then 69. Is NBAR useless as far
as
> TFTP is concerned.
>
> _______________________________________________________________________
> Subscription information may be found at:
> http://www.groupstudy.com/list/CCIELab.html

-----------------------------------------------------------------------------
-
  Help yourself to FREE treats served up daily at the Messenger Cafi. Stop by
today!



This archive was generated by hypermail 2.1.4 : Fri Nov 16 2007 - 13:11:15 ART