|
|
||||||||||||||
![]() ![]() The Cost of Security on Cisco Routers February 22, 1999
At Syracuse University, we've been using Cisco's IOS (Internetwork Operating Systems) for more than five years and have found that there are concessions that must be made when enabling ACLs on Cisco's enterprise routers, such as the 7500, 7200 and 8510 models. In this article, we'll present some recent findings from some 7200 testing we've performed. Don't Get Lost in the Process There is nothing mysterious about the way routers forward packets. Packets received on an interface are processed by the main CPU. Each packet is copied into memory and the routing table is consulted to determine the direction to forward the packet. Once the correct route and corresponding interface are chosen, packets are copied out of memory, onto the appropriate network. Of course, other tasks are involved, such as keeping the routing tables updated, but the forwarding process is performed for every single packet that traverses through the router. In Cisco parlance, the forwarding process is referred to as Process Switching. Cisco is constantly inventing new schemes to improve packet-forwarding performance, and all these schemes have different performance implications, which vary based on whether ACLs are used. Although the different switching methods employed can be a little confusing, one thing is clear: You would not want to push any traffic through a Cisco router that involves Process Switching. A Cisco 7500 using Process Switching is capable of forwarding only about 10,000 packets per second. Fortunately, Process Switching is rarely employed. Instead, a number of other switching techniques--including Fast Switching, Optimum Switching, Distributed Switching and Cisco Express Forwarding (CEF)--are more commonly used.
|
Page 1 | Next Page |
Best of the Web
Data deduplication: Declawing the clones
Data deduplication is emerging as a critically important new arrow in the storage administrator's quiver to answer hard questions about the increasing problem in storage growth costs.
Compression, Encryption, Deduplication, and Replication: Strange Bedfellows
One of the great ironies of storage technology is the inverse relationship between efficiency and security: Adding performance or reducing storage requirements almost always results in reducing the confidentiality, integrity, or availability of a system.
WAN Optimization Whitelists and Blacklists
Optimization is a fantastic way of saving money and creating really happy customers at the same time, but it doesn't work flawlessly for all applications.
WAN Optimization as a Managed Service: It's Not About the Cost
This insight examines how organizations outsourcing their WAN optimization initiatives to a third-party go about achieving their goals for application performance, reducing operational costs, and streamlining enterprise infrastructure.


Here
Here




