I dont think so, "debug ip packet" is ok if you use a very specific ACL,
IMHO.

I found very dangerous "debug ip nat detailed", I saw 7200 down because
of that command without too many nat :-P

El mar, 19-01-2010 a las 12:24 +0000, Dobbins, Roland escribió:
> On Jan 19, 2010, at 6:25 PM, Andre Schoppmeier wrote:
> 
> > Just have a question regarding FIB errors during packet debugging:
> 
> FYI, IP packet debug is generally considered to be too dangerous for use on 
> production boxes - it's a huge risk in terms of self-DoSing the router(s) in 
> question.  
> 
> -----------------------------------------------------------------------
> Roland Dobbins <[email protected]> // <http://www.arbornetworks.com>
> 
>     Injustice is relatively easy to bear; what stings is justice.
> 
>                         -- H.L. Mencken
> 
> 
> 
> _______________________________________________
> cisco-nsp mailing list  [email protected]
> https://puck.nether.net/mailman/listinfo/cisco-nsp
> archive at http://puck.nether.net/pipermail/cisco-nsp/


_______________________________________________
cisco-nsp mailing list  [email protected]
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/

Reply via email to