Understanding Flexible Packet Matching
Posted in Advanced Security, CCIE R&S, CCIE Security, Security on Jun 14th, 2009
Flexible Packet Matching is a new feature that allows for granular packet inspection in Cisco IOS routers. Using FPM you can match any string, byte or even bit at any position in the IP (or theoretically non-IP) packet. This may greatly aid in identifying and blocking network attacks using static patterns found in the attack traffic. This feature has some limitation though. ... [Read the rest of this entry -->]


