From: Khalid Nafie (knafie@xxxxxxxxxx)
Date: Mon Oct 08 2001 - 13:54:19 GMT-3
Dear all,
IP1----(E1)[R1](S0)---IP2
-to block address spoofing on Ehternet we deny any traffic that has
ehrtrnet ip segement as a source and comming from S0 , isn't it?
- IP inspect name fw tcp, udp does these statemnets eliminate the
need of using ACL that premts the H.323 traffic that is comming from the
outside as a reply? I mean does the inspection of UDP covers all the udp
traffic on all the ports range?
This archive was generated by hypermail 2.1.4 : Thu Jun 20 2002 - 22:33:14 GMT-3