Router IOS Firewall: Allow only internal hosts to initiate a TCP session. 
InternalHosts<--e1(Router)e0-->RemoteNetworks

access-list 100 permit tcp any any gt 1023 established

interface e0
ip access-group 100 in


"UDP packets don't establish a connection, they're literally fire and forget! A simple permit udp host xx.xx.xx.xx host xx.xx.xx.xx eq xx should be all that's required."

-------------------------------------------------------------
See Cisco document id 26448


Also see:

Reflexive ACLs
ip inspect command.



[ view entry ] ( 1553 views )   |  print article

<<First <Back | 10 | 11 | 12 | 13 | 14 | 15 | 16 | 17 | 18 | 19 | Next> Last>>



2024 By Angel Cool