Great Circle Associates Firewalls
(March 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Cisco Access control lists.
From: Darren Reed <avalon @ coombs . anu . edu . au>
Date: Thu, 21 Mar 1996 00:13:38 +1100 (EDT)
To: Firewalls @ GreatCircle . COM (Firewalls Mailing List)

I heard an interesting comment today, from a network engineer, who said
that Cisco had told him that using input and output acl's on the same
interface would produce unpredictable results and to rewrite the filters
to be "all output" or "all input" for a given interface (apparently they
tried, but things didn't happen as expected and that was Cisco's advice).

Is anyone actually using filters for both input and outut on an interface,
if so, what IOS rev., and is there any substance to this (ie buggy revcs of
the IOS) or does it just require things to be done "right" ?

thanks,
darren

Indexed By Date Previous: Re: Happening again
From: "W.C. Epperson" <epperson @ vak12ed . edu>
Next: Re: Security of Networked Workstations with dial-up PPP Internet!!!
From: "W.C. Epperson" <epperson @ vak12ed . edu>
Indexed By Thread Previous: Re: RE : Anti-Virus Products for Internet
From: System Administrator <admin @ dnsppp . net>
Next: Re: Cisco Access control lists.
From: Paul Ferguson <pferguso @ cisco . com>

Google
 
Search Internet Search www.greatcircle.com