<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPS traffic over performace limit in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ips-traffic-over-performace-limit/m-p/1593373#M65543</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Radim,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Oversubscription in IPS is at Interface level or Virtual Sensor level.&lt;/P&gt;&lt;P&gt;Hypothetically say IPS has 6 interfaces each being a gig port.&lt;/P&gt;&lt;P&gt;This does not mean IPS throughput is 6 gigs, since the inspection engine may not be able to handle 6 gig at a time.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For interface level oversubscription, if you send more traffic to an interface than it can handle, then you overwhelm its interface buffers.&lt;/P&gt;&lt;P&gt;The packets get dropped at the interface level.&lt;/P&gt;&lt;P&gt;The ' FIFO errors' counter under 'show interface' will show this error.&lt;/P&gt;&lt;P&gt;Packets dropped because too much traffic it being sent to virtual sensor than it can handle will be seen as 'missed packet percentage' counter.&lt;/P&gt;&lt;P&gt;I shall check if this traffic is dropped or passed through uninspected and let you know.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The throughput of the IPS depends on the type of traffic flowing through it.&lt;/P&gt;&lt;P&gt;Please check the document below which explains IPS performance with some data for 4270.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/prod/collateral/vpndevc/ps5729/ps5713/ps4077/prod_white_paper0900aecd806e7283.html"&gt;http://www.cisco.com/en/US/prod/collateral/vpndevc/ps5729/ps5713/ps4077/prod_white_paper0900aecd806e7283.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sid Chandrachud&lt;/P&gt;&lt;P&gt;Cisco TAC - Security Team&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 05 Mar 2011 22:03:02 GMT</pubDate>
    <dc:creator>Siddharth Chandrachud</dc:creator>
    <dc:date>2011-03-05T22:03:02Z</dc:date>
    <item>
      <title>IPS traffic over performace limit</title>
      <link>https://community.cisco.com/t5/network-security/ips-traffic-over-performace-limit/m-p/1593371#M65540</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;I could not find any information about traffic which is over declared IPS appliance performance (throughput) limit.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Those packets will be droped or will pass through without inspection?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Radim&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 12:17:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-traffic-over-performace-limit/m-p/1593371#M65540</guid>
      <dc:creator>Radim Jurica</dc:creator>
      <dc:date>2019-03-10T12:17:07Z</dc:date>
    </item>
    <item>
      <title>Re: IPS traffic over performace limit</title>
      <link>https://community.cisco.com/t5/network-security/ips-traffic-over-performace-limit/m-p/1593372#M65542</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just for clarification - I mean inline mode.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are there two possibilities depending on implementation? In case interface pairing packets will be bridged without inspection and in case VLAN pairing packets will be simply droped?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Radim&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Mar 2011 22:29:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-traffic-over-performace-limit/m-p/1593372#M65542</guid>
      <dc:creator>Radim Jurica</dc:creator>
      <dc:date>2011-03-03T22:29:11Z</dc:date>
    </item>
    <item>
      <title>Re: IPS traffic over performace limit</title>
      <link>https://community.cisco.com/t5/network-security/ips-traffic-over-performace-limit/m-p/1593373#M65543</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Radim,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Oversubscription in IPS is at Interface level or Virtual Sensor level.&lt;/P&gt;&lt;P&gt;Hypothetically say IPS has 6 interfaces each being a gig port.&lt;/P&gt;&lt;P&gt;This does not mean IPS throughput is 6 gigs, since the inspection engine may not be able to handle 6 gig at a time.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For interface level oversubscription, if you send more traffic to an interface than it can handle, then you overwhelm its interface buffers.&lt;/P&gt;&lt;P&gt;The packets get dropped at the interface level.&lt;/P&gt;&lt;P&gt;The ' FIFO errors' counter under 'show interface' will show this error.&lt;/P&gt;&lt;P&gt;Packets dropped because too much traffic it being sent to virtual sensor than it can handle will be seen as 'missed packet percentage' counter.&lt;/P&gt;&lt;P&gt;I shall check if this traffic is dropped or passed through uninspected and let you know.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The throughput of the IPS depends on the type of traffic flowing through it.&lt;/P&gt;&lt;P&gt;Please check the document below which explains IPS performance with some data for 4270.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/prod/collateral/vpndevc/ps5729/ps5713/ps4077/prod_white_paper0900aecd806e7283.html"&gt;http://www.cisco.com/en/US/prod/collateral/vpndevc/ps5729/ps5713/ps4077/prod_white_paper0900aecd806e7283.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sid Chandrachud&lt;/P&gt;&lt;P&gt;Cisco TAC - Security Team&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 05 Mar 2011 22:03:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-traffic-over-performace-limit/m-p/1593373#M65543</guid>
      <dc:creator>Siddharth Chandrachud</dc:creator>
      <dc:date>2011-03-05T22:03:02Z</dc:date>
    </item>
    <item>
      <title>Re: IPS traffic over performace limit</title>
      <link>https://community.cisco.com/t5/network-security/ips-traffic-over-performace-limit/m-p/1593374#M65544</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Sid,&lt;BR /&gt;thank you for answer. I am specially interested in this for VLAN pairing mode for IPS-4270 connected to Cat6500 through MultiEtherChannel.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I thing that like there is no possible hardware bypass in VLAN pairing mode its same for overloading, because of retagging process. But maybe. It depends on where retagging is taken.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you find something relevant, let me know please.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Radim&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 06 Mar 2011 20:13:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-traffic-over-performace-limit/m-p/1593374#M65544</guid>
      <dc:creator>Radim Jurica</dc:creator>
      <dc:date>2011-03-06T20:13:20Z</dc:date>
    </item>
  </channel>
</rss>

