NETWORK PRESENCE ABOUT SERVICES PRODUCTS TRAINING CONTACT US SEARCH SUPPORT
 


Search
display results
words begin  exact words  any words part 

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

RE: [FW1] Source port based filtering



Hi Skeeve,
 
The Cisco PIX can, so can a Cisco Router. The syntax is the same for each.
 
access-list 101 permit tcp host 10.20.30.40 eq 65000 host A.B.C.D eq 80
 
I can only really think of one application where it would be useful off the top of my head and that is for FTP traffic, but the PIX and Router IOS both know how to handle FTP without specifying the access-lists as above.
 
Custom apps that always sent on the same port to a random port would be what they would be used for.
 
Regards
JP

-----Original Message-----
From: Skeeve Stevens [mailto:[email protected]]
Subject: [FW1] Source port based filtering 


Does anyone know a practical application for source port packet filtering? 
Is even what I am asking logical? 
i.e. the port of the source packet (as opposed to the source address) 

Apparently FW1 does it, Cisco doesn't and has commentary saying 'why bother'. 

<<application/ms-tnef>>



 
----------------------------------

ABOUT SERVICES PRODUCTS TRAINING CONTACT US SEARCH SUPPORT SITE MAP LEGAL
   All contents © 2004 Network Presence, LLC. All rights reserved.