01-10-2011 01:59 AM - edited 03-06-2019 02:54 PM
Hello
I am working with in an organisation that is in need for layer 7 inspect. We need to match protocols like online games, file sharing and any other services that uses dynamic assigned ports.
What Cisco device is able to accomplish this?
//Rulif
01-12-2011 01:57 AM
Hello Rulif.
I have not an answer to your question but I was curious about. So I have decided to throw again your post.
May be Cisco implements only security at Layers 2,3 and 4. It would be quite logic too.
It would be appreciated even only a confirm about this inability.
Thanks.
01-12-2011 03:17 AM
Hi,
You can use NBAR in combination with a class map to do drop this type of traffic. See the attached link for an example based on blocking Skype.
https://supportforums.cisco.com/docs/DOC-5818
See also a Q&A reference guide for NBAR
Please remember to rate all posts that are helpful
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide