Great Circle Associates Firewalls
(October 1992)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Filters and interfaces.
From: Roland Acra <acra @ cisco . com>
Date: Mon, 5 Oct 92 11:35:20 MDT
To: afx @ muc . ibm . de (Andreas Siegert)
Cc: Firewalls @ GreatCircle . COM
In-reply-to: <9210051538 . AA14092 @ barolo . ak . munich . ibm . com>; from "Andreas Siegert" at Oct 5, 92 5:38 pm

Yes, indeed. Filters on Cisco routers are interface-specific.
A collection of filtering statements is defined as an "access-list",
which can then be applied to one or more interfaces. Distinct interfaces
on a given router can be configured with distinct access lists.

Note that these access lists affect outgoing (as opposed to incoming)
traffic on the interfaces they are applied upon.

Roland Acra
Cisco Systems Europe
acra @
 cisco .
 com

> 
> Darren Reed wrote:
> ...
> >    To reduce both the size of filter rulesets as well as increasing
> > throughput of non-filtered traffic, it would seem better to be able
> > to setup a different filter rule set for each interface connected to
> > the host.  Are there any working packet filters which are able to
> > operate in this way or does anyone know of any texts which discuss
> > this ?  With this approach, you could more easily block packets from
> > outside which were trying to be internal hosts.
> 
> Is't that the method the CISCO routers use?
> 
> afx
> -- 
> Andreas Siegert / Postmaster   IBM Deutschland GmbH   |   Never grep a yacc
> AIX Field Support Center       Pocci Strasse 11       |   by the i-node!
> Internet: afx @
 ibm .
 de           D-8000 Muenchen 2      |   Opinions are my own,
> VNET: SIEGERT @
 MUNIVM4          Voice: (49)-(89)-7670-509  not IBM's.
> 




References:
Indexed By Date Previous: Re: Filters and interfaces.
From: Brent Chapman <brent @ GreatCircle . COM>
Next: Re: Filters and interfaces.
From: Brent Chapman <brent @ GreatCircle . COM>
Indexed By Thread Previous: Filters and interfaces.
From: afx @ muc . ibm . de (Andreas Siegert)
Next: Re: Filters and interfaces.
From: smb @ ulysses . att . com

Google
 
Search Internet Search www.greatcircle.com