in

IEOC - Internetwork Expert's Online Community

Welcome to Internetwork Expert's Online Community - IEOC - a place for CCIE and CCENT candidates to connect, share, and learn. Our Online Community features CCIE forums and discussions for all tracks including Routing & Switching, Voice, Security, Service Provider, and Storage. Through these online communities you can discuss your questions with thousands of your peers, hundreds of CCIE's and Internetwork Expert's own team of world renowned CCIE instructors and authors, Brian Dennis - Quintuple CCIE #2210, Scott Morris - Quad CCIE #4713, Brian McGahan – Triple CCIE #8593, Petr Lapukhov - Quad CCIE #16379, Anthony Sequeira - CCIE #15626, Keith Barker - Dual CCIE #6783, and Marvin Greenlee - Triple CCIE #12237.
Latest post 01-01-2009 2:30 PM by Scott Morris. 7 replies.
Page 1 of 1 (8 items)
Sort Posts: Previous Next
  • 12-30-2008 2:40 PM

    Match protocol rtp audio VS udp access-group

    Wasnt having much luck finding this anywhere, possibly someone on this forum has the answer to this.  Are the following two class-map components the same?

     

    match protocol rtp audio

    OR

    match access-group VoIP

    ip access-list extended VoIP
    permit udp any any range 16384 32767

     

    Many thanks,

    Steve

    • Post Points: 20
  • 12-30-2008 3:45 PM In reply to

    RE: Match protocol rtp audio VS udp access-group

    It depends on how picky you are getting...
     
    Technically an audio stream is made up of a PAIR of UDP ports.  One is RTP and the other is RTCP (control).  AFAIK, the "match protocol rtp audio" will only pick up the RTP portion which is where most traffic will occur anyway.
     
    Your ACL will pick up both.
     
    Do you care?  I doubt it.  but that's just my opinion.  Asking the proctor will demonstrate knowledge of details, so I don't think there would be a problem with them expressing an opinion.
     


    Scott Morris, CCIE4 #4713, JNCIE-M #153, JNCIS-ER, CISSP, et al.
    CCSI/JNCI-M/JNCI-ER
    Senior CCIE Instructor

    smorris@internetworkexpert.com

     

    Internetwork Expert, Inc.
    http://www.InternetworkExpert.com
    Toll Free: 877-224-8987
    Outside US: 775-826-4344
    Online Community: http://tinyurl.com/6dmnsu
    CCIE Blog: http://tinyurl.com/2nxxaq


    Knowledge is power.
    Power corrupts.
    Study hard and be Eeeeviiiil......


    From: ccie-rs@ieoc.com [mailto:ccie-rs@ieoc.com] On Behalf Of snowell
    Sent: Tuesday, December 30, 2008 5:44 PM
    To: smorris@internetworkexpert.com
    Subject: [CCIE R&S] Match protocol rtp audio VS udp access-group

    Wasnt having much luck finding this anywhere, possibly someone on this forum has the answer to this.  Are the following two class-map components the same?

     

    match protocol rtp audio

    OR

    match access-group VoIP

    ip access-list extended VoIP
    permit udp any any range 16384 32767

     

    Many thanks,

    Steve




    Internetwork Expert - The Industry Leader in CCIE Preparation
    http://www.internetworkexpert.com

    Subscription information may be found at:
    http://www.ieoc.com/forums/ForumSubscriptions.aspx
    • Post Points: 20
  • 12-30-2008 4:09 PM In reply to

    RE: Match protocol rtp audio VS udp access-group

    Hi Scott,

    Sounds like if I got a task requesting that I “prioritize voice traffic”,  if I used the match protocol option it would be an incorrect answer because I am missing the RTCP traffic at that point.  Right?

     

    BTW, its steve nowell from Cisco here – hope you have a great new years!

    Thanks!

     

    From: ccie-rs@ieoc.com [mailto:ccie-rs@ieoc.com] On Behalf Of Scott Morris
    Sent: Tuesday, December 30, 2008 6:49 PM
    To: Steve Nowell (snowell)
    Subject: RE: [CCIE R&S] Match protocol rtp audio VS udp access-group

     

    It depends on how picky you are getting...

     

    Technically an audio stream is made up of a PAIR of UDP ports.  One is RTP and the other is RTCP (control).  AFAIK, the "match protocol rtp audio" will only pick up the RTP portion which is where most traffic will occur anyway.

     

    Your ACL will pick up both.

     

    Do you care?  I doubt it.  but that's just my opinion.  Asking the proctor will demonstrate knowledge of details, so I don't think there would be a problem with them expressing an opinion.

     


    Scott Morris, CCIE4 #4713, JNCIE-M #153, JNCIS-ER, CISSP, et al.
    CCSI/JNCI-M/JNCI-ER
    Senior CCIE Instructor

    smorris@internetworkexpert.com

     

    Internetwork Expert, Inc.
    http://www.InternetworkExpert.com
    Toll Free: 877-224-8987
    Outside US: 775-826-4344
    Online Community: http://tinyurl.com/6dmnsu
    CCIE Blog: http://tinyurl.com/2nxxaq

    Knowledge is power.
    Power corrupts.
    Study hard and be Eeeeviiiil......

     


    From: ccie-rs@ieoc.com [mailto:ccie-rs@ieoc.com] On Behalf Of snowell
    Sent: Tuesday, December 30, 2008 5:44 PM
    To: smorris@internetworkexpert.com
    Subject: [CCIE R&S] Match protocol rtp audio VS udp access-group

    Wasnt having much luck finding this anywhere, possibly someone on this forum has the answer to this.  Are the following two class-map components the same?

     

    match protocol rtp audio

    OR

    match access-group VoIP

    ip access-list extended VoIP
    permit udp any any range 16384 32767

     

    Many thanks,

    Steve




    Internetwork Expert - The Industry Leader in CCIE Preparation
    http://www.internetworkexpert.com

    Subscription information may be found at:
    http://www.ieoc.com/forums/ForumSubscriptions.aspx




    Internetwork Expert - The Industry Leader in CCIE Preparation
    http://www.internetworkexpert.com

    Subscription information may be found at:
    http://www.ieoc.com/forums/ForumSubscriptions.aspx

    • Post Points: 20
  • 12-30-2008 5:29 PM In reply to

    RE: Match protocol rtp audio VS udp access-group

    Hey Steve!  Hope you're enjoying your "extra" week off!  :)  Have a great new year's as well!
     
    As for the prioritization, I'm not sure I'd think that much about it.  If you look at the protocol statistics, you'll find very little control traffic compared to the audio stream itself.  Depending on your setup, and versioning, there's a certain amount anyway...  DSCP EF versus DSCP 26 (AF31) for stream and control.
     
    So if you are matching the ACL and DSCP EF, you're already separating things anyway.  :)
     
    I'm just not entirely convinced that the R&S lab is getting that specific on voice stuff, but better to ask the proctor about the details.  From a real-life standpoint, most people I know just go ahead and prioritize both RTP and RTCP just to keep things simple.  The result is that there's "not much more" traffic sent at high priority, so you aren't really creating problems to the rest of your QoS setup.
     
    HTH,
     
    Scott


    From: ccie-rs@ieoc.com [mailto:ccie-rs@ieoc.com] On Behalf Of snowell
    Sent: Tuesday, December 30, 2008 7:14 PM
    To: smorris@internetworkexpert.com
    Subject: RE: [CCIE R&S] Match protocol rtp audio VS udp access-group

    Hi Scott,

    Sounds like if I got a task requesting that I “prioritize voice traffic”,  if I used the match protocol option it would be an incorrect answer because I am missing the RTCP traffic at that point.  Right?

     

    BTW, its steve nowell from Cisco here – hope you have a great new years!

    Thanks!

     

    From: ccie-rs@ieoc.com [mailto:ccie-rs@ieoc.com] On Behalf Of Scott Morris
    Sent: Tuesday, December 30, 2008 6:49 PM
    To: Steve Nowell (snowell)
    Subject: RE: [CCIE R&S] Match protocol rtp audio VS udp access-group

     

    It depends on how picky you are getting...

     

    Technically an audio stream is made up of a PAIR of UDP ports.  One is RTP and the other is RTCP (control).  AFAIK, the "match protocol rtp audio" will only pick up the RTP portion which is where most traffic will occur anyway.

     

    Your ACL will pick up both.

     

    Do you care?  I doubt it.  but that's just my opinion.  Asking the proctor will demonstrate knowledge of details, so I don't think there would be a problem with them expressing an opinion.

     


    Scott Morris, CCIE4 #4713, JNCIE-M #153, JNCIS-ER, CISSP, et al.
    CCSI/JNCI-M/JNCI-ER
    Senior CCIE Instructor

    smorris@internetworkexpert.com

     

    Internetwork Expert, Inc.
    http://www.InternetworkExpert.com
    Toll Free: 877-224-8987
    Outside US: 775-826-4344
    Online Community: http://tinyurl.com/6dmnsu
    CCIE Blog: http://tinyurl.com/2nxxaq

    Knowledge is power.
    Power corrupts.
    Study hard and be Eeeeviiiil......

     


    From: ccie-rs@ieoc.com [mailto:ccie-rs@ieoc.com] On Behalf Of snowell
    Sent: Tuesday, December 30, 2008 5:44 PM
    To: smorris@internetworkexpert.com
    Subject: [CCIE R&S] Match protocol rtp audio VS udp access-group

    Wasnt having much luck finding this anywhere, possibly someone on this forum has the answer to this.  Are the following two class-map components the same?

     

    match protocol rtp audio

    OR

    match access-group VoIP

    ip access-list extended VoIP
    permit udp any any range 16384 32767

     

    Many thanks,

    Steve




    Internetwork Expert - The Industry Leader in CCIE Preparation
    http://www.internetworkexpert.com

    Subscription information may be found at:
    http://www.ieoc.com/forums/ForumSubscriptions.aspx




    Internetwork Expert - The Industry Leader in CCIE Preparation
    http://www.internetworkexpert.com

    Subscription information may be found at:
    http://www.ieoc.com/forums/ForumSubscriptions.aspx




    Internetwork Expert - The Industry Leader in CCIE Preparation
    http://www.internetworkexpert.com

    Subscription information may be found at:
    http://www.ieoc.com/forums/ForumSubscriptions.aspx
    • Post Points: 20
  • 12-30-2008 6:26 PM In reply to

    • bam
    • Top 10 Contributor
    • Joined on 07-11-2008
    • Elite
    • Points 5,050

    Re: RE: Match protocol rtp audio VS udp access-group

    According to the CR, "It is important to note that the NBAR RTP Payload Classification feature does not identify RTCP packets and that RTCP packets run on odd-numbered ports while RTP packets run on even-numbered ports."

    What that means to me is that 'match protocol rtp' only matches the even numbers in the range 16384-32767. (If that's wrong, please let me know.) RTCP is voice traffic, right? But then again so is H.323 and SIP, etc... So I'm not sure where you draw the line. The 'match protocol (NBAR)' command lists a bunch of Voice types in Table 16.

    If it were me, I'd use the ext ACL. Or if forced to use NBAR then, at the very least, match both rtp and rtcp.

    Feedback?

    • Post Points: 20
  • 12-30-2008 6:49 PM In reply to

    RE: RE: Match protocol rtp audio VS udp access-group

    If you are painting that broad a stroke, neither method will match SIP...  SIP is tcp/5060 by default.  So we'll keep things a little more simplistic here!  :)  H.323 is all we'll worry about for now.
     
    Scott
     


    From: ccie-rs@ieoc.com [mailto:ccie-rs@ieoc.com] On Behalf Of bam
    Sent: Tuesday, December 30, 2008 9:29 PM
    To: smorris@internetworkexpert.com
    Subject: Re: [CCIE R&S] RE: Match protocol rtp audio VS udp access-group

    According to the CR, "It is important to note that the NBAR RTP Payload Classification feature does not identify RTCP packets and that RTCP packets run on odd-numbered ports while RTP packets run on even-numbered ports."

    What that means to me is that 'match protocol rtp' only matches the even numbers in the range 16384-32767. (If that's wrong, please let me know.) RTCP is voice traffic, right? But then again so is H.323 and SIP, etc... So I'm not sure where you draw the line. The 'match protocol (NBAR)' command lists a bunch of Voice types in Table 16.

    If it were me, I'd use the ext ACL. Or if forced to use NBAR then, at the very least, match both rtp and rtcp.

    Feedback?




    Internetwork Expert - The Industry Leader in CCIE Preparation
    http://www.internetworkexpert.com

    Subscription information may be found at:
    http://www.ieoc.com/forums/ForumSubscriptions.aspx
    • Post Points: 20
  • 12-31-2008 2:25 AM In reply to

    • bam
    • Top 10 Contributor
    • Joined on 07-11-2008
    • Elite
    • Points 5,050

    Re: RE: RE: Match protocol rtp audio VS udp access-group

    my point exactly. how do you define 'voice' when a task commands you to prioritize it? I guess that's a question for the proctor-ologist.

    • Post Points: 20
  • 01-01-2009 2:30 PM In reply to

    Re: RE: RE: Match protocol rtp audio VS udp access-group

    Yup, that would be my take on it.  But "standard" H.323 is the safest bet there.  That was the only voice that used to be in the R&S lab when voice was an actual topic!

    Scott



    ----- Original Message -----
    From: "bam" <bounce-bam@ieoc.com>
    Sent: Wed, December 31, 2008 3:25
    Subject: Re: [CCIE R&S] RE: RE: Match protocol rtp audio VS udp access-group

    my point exactly. how do you define 'voice' when a task commands you to prioritize it? I guess that's a question for the proctor-ologist.



    --
    View this message online at: http://ieoc.com/forums/p/4492/14543.aspx#14543
    --
    Internetwork Expert - The Industry Leader in CCIE Preparation
    http://www.internetworkexpert.com

    Subscription information may be found at:
    http://www.ieoc.com/forums/ForumSubscriptions.aspx
    • Post Points: 5
Page 1 of 1 (8 items)
IEOC CCIE Forums Internetwork Expert CCIE Training
About IEOC | Terms of Use | RSS | Privacy Policy
© 2009 Internetwork Expert, Inc. All Rights Reserved