<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Tutorial: How to use Cisco MQC &amp; NBAR to filter websites like Youtube</title>
	<atom:link href="http://ardenpackeer.com/qos-voip/tutorial-how-to-use-cisco-mqc-nbar-to-filter-websites-like-youtube/feed/" rel="self" type="application/rss+xml" />
	<link>http://ardenpackeer.com/qos-voip/tutorial-how-to-use-cisco-mqc-nbar-to-filter-websites-like-youtube/</link>
	<description>Helping You Become a Network Ninja</description>
	<lastBuildDate>Tue, 09 Mar 2010 02:21:31 -0700</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Jack</title>
		<link>http://ardenpackeer.com/qos-voip/tutorial-how-to-use-cisco-mqc-nbar-to-filter-websites-like-youtube/comment-page-1/#comment-18417</link>
		<dc:creator>Jack</dc:creator>
		<pubDate>Wed, 20 Jan 2010 18:50:08 +0000</pubDate>
		<guid isPermaLink="false">http://ardenpackeer.com/qos-voip/tutorial-how-to-use-cisco-mqc-nbar-to-filter-websites-like-youtube/#comment-18417</guid>
		<description>nice read...is it possible to send me an example to block everything(streaming videos) but allowed youtube and some other video streaming website.

can this be done on nbar/qos.

ciao,
jr</description>
		<content:encoded><![CDATA[<p>nice read&#8230;is it possible to send me an example to block everything(streaming videos) but allowed youtube and some other video streaming website.</p>
<p>can this be done on nbar/qos.</p>
<p>ciao,<br />
jr</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: class-map &#8211; match protocol http url command</title>
		<link>http://ardenpackeer.com/qos-voip/tutorial-how-to-use-cisco-mqc-nbar-to-filter-websites-like-youtube/comment-page-1/#comment-12957</link>
		<dc:creator>class-map &#8211; match protocol http url command</dc:creator>
		<pubDate>Sat, 15 Aug 2009 04:13:18 +0000</pubDate>
		<guid isPermaLink="false">http://ardenpackeer.com/qos-voip/tutorial-how-to-use-cisco-mqc-nbar-to-filter-websites-like-youtube/#comment-12957</guid>
		<description>[...] I have read this link from Arden, thanks Arden: http://ardenpackeer.com/qos-voip/tutorial-how-to-use-cisco-mqc-nbar-to-filter-websites-like-youtube/ [...]</description>
		<content:encoded><![CDATA[<p>[...] I have read this link from Arden, thanks Arden: <a href="http://ardenpackeer.com/qos-voip/tutorial-how-to-use-cisco-mqc-nbar-to-filter-websites-like-youtube/" rel="nofollow">http://ardenpackeer.com/qos-voip/tutorial-how-to-use-cisco-mqc-nbar-to-filter-websites-like-youtube/</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mesut Cap</title>
		<link>http://ardenpackeer.com/qos-voip/tutorial-how-to-use-cisco-mqc-nbar-to-filter-websites-like-youtube/comment-page-1/#comment-12414</link>
		<dc:creator>Mesut Cap</dc:creator>
		<pubDate>Thu, 23 Jul 2009 11:16:38 +0000</pubDate>
		<guid isPermaLink="false">http://ardenpackeer.com/qos-voip/tutorial-how-to-use-cisco-mqc-nbar-to-filter-websites-like-youtube/#comment-12414</guid>
		<description>Great tutorial very useful, thank you.</description>
		<content:encoded><![CDATA[<p>Great tutorial very useful, thank you.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: elaheh</title>
		<link>http://ardenpackeer.com/qos-voip/tutorial-how-to-use-cisco-mqc-nbar-to-filter-websites-like-youtube/comment-page-1/#comment-12138</link>
		<dc:creator>elaheh</dc:creator>
		<pubDate>Tue, 14 Jul 2009 08:50:26 +0000</pubDate>
		<guid isPermaLink="false">http://ardenpackeer.com/qos-voip/tutorial-how-to-use-cisco-mqc-nbar-to-filter-websites-like-youtube/#comment-12138</guid>
		<description>great tutorial.This was so benefit for me.

thank you</description>
		<content:encoded><![CDATA[<p>great tutorial.This was so benefit for me.</p>
<p>thank you</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rajitha</title>
		<link>http://ardenpackeer.com/qos-voip/tutorial-how-to-use-cisco-mqc-nbar-to-filter-websites-like-youtube/comment-page-1/#comment-11614</link>
		<dc:creator>Rajitha</dc:creator>
		<pubDate>Thu, 02 Jul 2009 07:05:11 +0000</pubDate>
		<guid isPermaLink="false">http://ardenpackeer.com/qos-voip/tutorial-how-to-use-cisco-mqc-nbar-to-filter-websites-like-youtube/#comment-11614</guid>
		<description>Great one. very useful. I implemented this to cater one of my customer requirement.By the way do you have any idea of blocking P2P application &amp; instant messaging. there are options to do this by using SDM. but i don&#039;t like that as it highly rely on IOS capabilities.</description>
		<content:encoded><![CDATA[<p>Great one. very useful. I implemented this to cater one of my customer requirement.By the way do you have any idea of blocking P2P application &amp; instant messaging. there are options to do this by using SDM. but i don&#8217;t like that as it highly rely on IOS capabilities.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Arden Packeer, CCIE #20716</title>
		<link>http://ardenpackeer.com/qos-voip/tutorial-how-to-use-cisco-mqc-nbar-to-filter-websites-like-youtube/comment-page-1/#comment-10165</link>
		<dc:creator>Arden Packeer, CCIE #20716</dc:creator>
		<pubDate>Thu, 21 May 2009 10:35:57 +0000</pubDate>
		<guid isPermaLink="false">http://ardenpackeer.com/qos-voip/tutorial-how-to-use-cisco-mqc-nbar-to-filter-websites-like-youtube/#comment-10165</guid>
		<description>@Broeisi: Nbar Protocol-Discovery is not required for classification</description>
		<content:encoded><![CDATA[<p>@Broeisi: Nbar Protocol-Discovery is not required for classification</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Broeisi</title>
		<link>http://ardenpackeer.com/qos-voip/tutorial-how-to-use-cisco-mqc-nbar-to-filter-websites-like-youtube/comment-page-1/#comment-10028</link>
		<dc:creator>Broeisi</dc:creator>
		<pubDate>Sun, 17 May 2009 09:48:06 +0000</pubDate>
		<guid isPermaLink="false">http://ardenpackeer.com/qos-voip/tutorial-how-to-use-cisco-mqc-nbar-to-filter-websites-like-youtube/#comment-10028</guid>
		<description>Arden,

To use nbar for classification don&#039;t you have to turn on nbar protocol-discovery??

Cheers,

Broeisi</description>
		<content:encoded><![CDATA[<p>Arden,</p>
<p>To use nbar for classification don&#8217;t you have to turn on nbar protocol-discovery??</p>
<p>Cheers,</p>
<p>Broeisi</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Salah</title>
		<link>http://ardenpackeer.com/qos-voip/tutorial-how-to-use-cisco-mqc-nbar-to-filter-websites-like-youtube/comment-page-1/#comment-7792</link>
		<dc:creator>Salah</dc:creator>
		<pubDate>Thu, 19 Mar 2009 21:15:03 +0000</pubDate>
		<guid isPermaLink="false">http://ardenpackeer.com/qos-voip/tutorial-how-to-use-cisco-mqc-nbar-to-filter-websites-like-youtube/#comment-7792</guid>
		<description>this is from the best topics I have ever read, easy well prepared.

thanks  Arden 

keep it up

Salah</description>
		<content:encoded><![CDATA[<p>this is from the best topics I have ever read, easy well prepared.</p>
<p>thanks  Arden </p>
<p>keep it up</p>
<p>Salah</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dale</title>
		<link>http://ardenpackeer.com/qos-voip/tutorial-how-to-use-cisco-mqc-nbar-to-filter-websites-like-youtube/comment-page-1/#comment-7290</link>
		<dc:creator>Dale</dc:creator>
		<pubDate>Tue, 24 Feb 2009 06:12:58 +0000</pubDate>
		<guid isPermaLink="false">http://ardenpackeer.com/qos-voip/tutorial-how-to-use-cisco-mqc-nbar-to-filter-websites-like-youtube/#comment-7290</guid>
		<description>In the last example, the &#039;match protocol http mime&#039; statements, if matched, won&#039;t be actioned with a &#039;drop&#039;.

I tested this extensively in my lab -- same basic topology as yours -- and found that some (not all) actions associated with a class using &#039;match protocol http mime&#039; only worked when the policy-map was applied in the *server -&gt; client* direction.

Using your example topology, if the policy-map was applied as an input policy on R2-s1/0, it would successfully classify the traffic but the &#039;drop&#039; action wouldn&#039;t take effect.

If applied as an input policy on R2-s1/1, it would work as expected.

If applied as an output policy on R2-s1/0, it would work as expected.

If applied as an output policy on R2-s1/1, it would classify the traffic but the &#039;drop&#039; action wouldn&#039;t take effect.

My tests were conducted using 2811s and IOS 12.4(23).

I&#039;m interested in your thoughts on this -- did you actually verify that, for example, R2 drops the HTTP response from R2 when the content type is &quot;application/x-shockwave-flash&quot; ?

I recreated your exact topology, then added &#039;match protocol http mime &quot;image/jpeg&quot;&#039; to the &#039;INTERNET-SCUM&#039; class-map. I was able to copy &quot;picture.jpg&quot; from R3 to R1 successfully.

Cheers!</description>
		<content:encoded><![CDATA[<p>In the last example, the &#8216;match protocol http mime&#8217; statements, if matched, won&#8217;t be actioned with a &#8216;drop&#8217;.</p>
<p>I tested this extensively in my lab &#8212; same basic topology as yours &#8212; and found that some (not all) actions associated with a class using &#8216;match protocol http mime&#8217; only worked when the policy-map was applied in the *server -&gt; client* direction.</p>
<p>Using your example topology, if the policy-map was applied as an input policy on R2-s1/0, it would successfully classify the traffic but the &#8216;drop&#8217; action wouldn&#8217;t take effect.</p>
<p>If applied as an input policy on R2-s1/1, it would work as expected.</p>
<p>If applied as an output policy on R2-s1/0, it would work as expected.</p>
<p>If applied as an output policy on R2-s1/1, it would classify the traffic but the &#8216;drop&#8217; action wouldn&#8217;t take effect.</p>
<p>My tests were conducted using 2811s and IOS 12.4(23).</p>
<p>I&#8217;m interested in your thoughts on this &#8212; did you actually verify that, for example, R2 drops the HTTP response from R2 when the content type is &#8220;application/x-shockwave-flash&#8221; ?</p>
<p>I recreated your exact topology, then added &#8216;match protocol http mime &#8220;image/jpeg&#8221;&#8216; to the &#8216;INTERNET-SCUM&#8217; class-map. I was able to copy &#8220;picture.jpg&#8221; from R3 to R1 successfully.</p>
<p>Cheers!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Roger</title>
		<link>http://ardenpackeer.com/qos-voip/tutorial-how-to-use-cisco-mqc-nbar-to-filter-websites-like-youtube/comment-page-1/#comment-6933</link>
		<dc:creator>Roger</dc:creator>
		<pubDate>Mon, 09 Feb 2009 21:09:27 +0000</pubDate>
		<guid isPermaLink="false">http://ardenpackeer.com/qos-voip/tutorial-how-to-use-cisco-mqc-nbar-to-filter-websites-like-youtube/#comment-6933</guid>
		<description>Hi Arden,

matching on url needs to be applied in outbound direction isn&#039;t it? I mean in this way you can prevent the client from accessing that page.
If you want to prevent him downloading the page you need to match based on mime types, isn&#039;t it?

regards

Roger</description>
		<content:encoded><![CDATA[<p>Hi Arden,</p>
<p>matching on url needs to be applied in outbound direction isn&#8217;t it? I mean in this way you can prevent the client from accessing that page.<br />
If you want to prevent him downloading the page you need to match based on mime types, isn&#8217;t it?</p>
<p>regards</p>
<p>Roger</p>
]]></content:encoded>
	</item>
</channel>
</rss>
