>>ps. When I talked to Cisco Tech Support they couldn't understand why anyone
>>would even want to filter by source port.
>I don't understand why you would want to filter by source port either.
Given x.y.z.0 as your internal network:
access-list 101 permit tcp any eq ftp-data x.y.z.0 gt 1023
It's sure not perfect, but if you don't have an active gateway, it's a tiny
bit better than just allowing random TCP connections to internal high ports.
Scott Hazen Mueller | scott @
ORG or tandem!zorch!scott