North American Network Operators Group|
Date Prev | Date Next | Date Index | Thread Index | Author Index | Historical
PBR needing to hit the cpu?
Just curious, do most vendors' hardware need to hit the cpu when doing policy-based routing? I found one of my border routers' cpu's on the bad end of a DDoS but once I turned off a not necessarily required setup to force some outbound traffic to take a specific outbound link via PBR, the DDoS traffic was no longer an issue. It was only about 200 Mbit so I hadn't expected it to be an issue but apparently it was; I was surprised when support told me the PBR was making traffic hit the cpu. TIA, David