cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
799
Views
0
Helpful
2
Replies

IDS and active X

peterson.dave
Level 1
Level 1

Has anybody seen a situation where IDS configured on a router slows down active x apps? I enabled IDS on a few routers we have and all of a sudden certain apps like TrackIT started to take an additional 45 seconds to load. Turn IDS off and everything loads right away?

Has anybody seen this? Has anybody used access-lists referenced in IDS to filter out boxes with similar problems? If so how did you find that it worked?

Thanks,

Dave

2 Replies 2

gabelar
Level 1
Level 1

Dave I can see potential for this happening. When IDS is enabled in the router it will inspect HTTP layer seven traffic. This will slow down active x and Java downloads. Inline inspection on routers was really designed for use with accelrator cards. If you have a PIX or IDS use that for DPI and let the router just forward packets. Also FYP - The new ISR routers (1800, 2800, 3800) are much more efficient for IDS.

This would make sense. I can run IDS out without any slowing, but when I add IDS IN the app slows to a crawl.

You are right though the new 2800 are much more effecient at IPS. Though the SDM gets a little weird with the java sometimes?

Review Cisco Networking for a $25 gift card