Denied packets process-switched - no longer?

Craig A. Huegen c-huegen at
Fri Aug 29 15:45:48 UTC 1997

On Fri, 29 Aug 1997, Jeffrey S. Curtis wrote:

==>Warning: possibly useful operational content follows.  Read at your own risk.
==>Regarding the possible denial-of-service implications of cisco routers
==>process-switching packets which have been denied by an access-list (as
==>was mentioned previously on this list), I received the following update
==>in this morning's list-of-bugs-and-their-new-status via email:

I've tested this image in my lab and it works very well.  2 pps head to
process level to send unreachables, the rest are quickly dropped in the
fast path.


More information about the NANOG mailing list