Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Firewalls
[Top] [All Lists]

RE: Cisco CBAC

Subject: RE: Cisco CBAC
Date: Mon, 25 Oct 2004 10:00:59 +0100
CBAC works differently because it modifies inbound access-list according
to outbound traffic.

 

Your problem with FTP may be that you have not specified FTP as an
outbound protocol. 

ie

ip inspect name rule ftp

 

simply using

ip inspect name rule tcp

 

is not good enough because FTP changes inbound ports for the data
transmit operation

 

HTH

 

Andy

________________________________

From: Dan Tesch [mailto:dan.tesch@comcast.net] 
Sent: 22 October 2004 04:36
To: firewalls@securityfocus.com
Subject: Cisco CBAC

 

Since starting to work with a new company which is using

a Cisco 2611 router with firewall IOS, I have noticed too many

times problems with downloading from certain FTP sites,

some won't work at all - problems downloading from websites

and applications used from vendor websites having problems.

 

As I have studied CBAC and come to understand what it does,

I am starting to wonder if this could be causing some of the

problems - Has anyone else had similar experiences?  why

does a Cisco router with this feature work differently than a

standard NAT router?

 

Thanks

<Prev in Thread] Current Thread [Next in Thread>