Cisco Operations Order
Posted January 19th, 2008 by wayland
Details the order of operations for a Cisco. This is the most complete list I've seen anywhere, and as you can see, it's compiled from multiple sources.
| General Areas | Inside Cisco IOS Software Architecture, posted here |
NAT order of Operations | QoS order of Operations | |
|---|---|---|---|---|
| Input | Compression / Decompression | If IPSec then check input Access list |
|
|
| Encryption | decryption - for CET (Cisco Encryption Technology) or IPSec | |||
| Check inbound/input access-list | ||||
| Unicast reverse path check |
|
|||
| Check input rate limits | ||||
|
|
|
|||
| Inspection subsystem (firewall features) | ||||
| Inbound: NAT outside to inside (global to local translation) | ||||
| Routing |
|
|||
| Policy routing | ||||
| Routing | ||||
| Web cache redirect | ||||
| Output | Outbound: NAT inside to outside (local to global translation) |
|
||
| Encryption | Crypto (check map and mark for encryption) | |||
| Check output access-list (packet filters) | ||||
| Inspection subsystem final checks (firewall features) |
and Low Latency Queueing (LLQ)), and Weighted Random Early Detection (WRED) |
|||
| TCP intercept processing | ||||
| Encryption | ||||
On the inbound path, a packet is classified before it is switched. On the outbound path, a packet is classified after it is switched.
Note: Input Network-Based Application Recognition (NBAR) happens after ACLs and before policy-based routing.
Bookmark/Search this post with:
- Login or register to post comments
- Printer-friendly version
Delicious
Digg
StumbleUpon
Propeller
Reddit
Magnoliacom
Newsvine
Furl
Facebook
Google
Yahoo
Technorati
Icerocket