Friday 28 March 2008

Network Based Application Recognition - NBAR

NBAR is capable of detecting applications/flows through a router. It is limited in the applications that it can recognise, PDLM's can be added to NBAR allowing recognition of additional applications. NBAR is simpler than access-lists and also supports HTTP MIME types, and stateful connections.

NBAR can be integrated into QoS to identify traffic and classify, using protocol-discovery.

ip nbar pdlm name_of_pdlm - Add a new PDLM located in flash
ip nbar port-map name_of_protocol tcp/udp port_number - map protocol to port
ip nbar protocol-discovery - enable NBAR protocol discovery on an interface

match protocol protocol_name - identify traffic in class-map using NBAR.

http://www.cisco.com/pcgi-bin/tablebuild.pl/pdlm - Download PDLMs

No comments: