02-08-2005 08:47 AM - edited 03-10-2019 01:16 AM
Has anybody seen a situation where IDS configured on a router slows down active x apps? I enabled IDS on a few routers we have and all of a sudden certain apps like TrackIT started to take an additional 45 seconds to load. Turn IDS off and everything loads right away?
Has anybody seen this? Has anybody used access-lists referenced in IDS to filter out boxes with similar problems? If so how did you find that it worked?
Thanks,
Dave
02-08-2005 04:05 PM
Dave I can see potential for this happening. When IDS is enabled in the router it will inspect HTTP layer seven traffic. This will slow down active x and Java downloads. Inline inspection on routers was really designed for use with accelrator cards. If you have a PIX or IDS use that for DPI and let the router just forward packets. Also FYP - The new ISR routers (1800, 2800, 3800) are much more efficient for IDS.
02-09-2005 06:52 AM
This would make sense. I can run IDS out without any slowing, but when I add IDS IN the app slows to a crawl.
You are right though the new 2800 are much more effecient at IPS. Though the SDM gets a little weird with the java sometimes?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide