Prev | Current Page 366 | Next

Yusuf Bhaiji

"Network Security Technologies and Solutions"


MQC provides comprehensive classification and marking solutions with a complete set of capabilities to classify
and mark traffic based on any Layer 2 or Layer 3 fields. MQC extends the capability to intelligently classify Layer
4 through Layer 7 protocols, using the integrated Network Based Application Recognition (NBAR) technology in
the IOS. MQC offers a single-rate and two-rate policer, which allows for packet re-marking (Layer 2 and Layer
3) or dropping policies to control traffic at the network edges/aggregation points.
The MQC allows for the Unconditional Packet Discard feature in which traffic that matches certain criteria can be
unconditionally dropped. This feature allows discarding (drop action inside a traffic class in a policy map)
without any further system processing and almost no performance impact. This function is very useful in the
security context because it allows the user to discard any packets for nonessential applications (such as Internet
browsing applications or unauthorized file-sharing P2P applications) while allocating system resources to more
essential applications.
Configuring MQC is a three-step process, which is outlined in the list that follows and depicted in Figure 7-7.


Pages:
354 355 356 357 358 359 360 361 362 363 364 365 366 367 368 369 370 371 372 373 374 375 376 377 378