cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements

Community Helping Community

1175
Views
15
Helpful
4
Replies

Matching ICMP in class maps

What's the difference between these two approaches and which one is recommended in what scenarios?

ip access-list extended ICMP

permit icmp any any

class-map ICMP

match access-group name ICMP

vs

class-map ICMP

match protocol ICMP

Everyone's tags (3)
4 REPLIES 4
Advisor

Matching ICMP in class maps

Hi,

they do the same thing but  by using the match protocol you are leveraging either NBAR if you do it for QoS or PAM if you do it for ZBF.with the ACL you could be more granular by specifying the code and subcode.

Regards

Alain

Don't forget to rate helpful posts.

Don't forget to rate helpful posts.
Beginner

Matching ICMP in class maps

I am with the similar query in my mind and ultimately reach to this discussion.

But in CCIE R&S LAB, what should be the correct approach?

Again is there ANY technical functionality difference between these two methods.

Rising star

Matching ICMP in class maps

In the CCIE lab you can use any technology you wish unless there are restrictions. If they wanted you to use ACLs the task could be worded like "Use a feature that uses the least amount of CPU to perform the task". If they wanted NBAR it could be something like "Use a feature that inspects at layer 7 to perform the classification".

Daniel Dib
CCIE #37149

Please rate helpful posts.

Daniel Dib
CCIE #37149
CCDE #20160011

Please rate helpful posts.
Highlighted
Beginner

Matching ICMP in class maps

Thanks Daniel,

Very helpful and to the point response.

CreatePlease to create content
Content for Community-Ad