Re: Fw: To correct DLSW NetBIOS filter

From: kym blair (kymblair@hotmail.com)
Date: Thu Nov 07 2002 - 09:47:04 GMT-3


Nguyen,

Per Fred Ingham (I think everyone agrees that Fred is the #1 authority on
SNA and NETBIOS filters):

NETBIOS filter:

  access-list 200 permit 0xF0F0 0x0101

SNA filter:

  access-list 200 permit 0x0000 0x0D0D

Applied to DLSW:

  dlsw remote-peer 0 tcp X.X.X.X lsap-output-list 200

HTH, Kym

>From: "Nguyen Hoang Long" <ng-hlong@hn.vnn.vn>
>Reply-To: "Nguyen Hoang Long" <ng-hlong@hn.vnn.vn>
> To: <ccielab@groupstudy.com>
>Subject: Fw: To correct DLSW NetBIOS filter
>Date: Thu, 7 Nov 2002 15:18:53 +0700
>
>Hi Group,
>This is my second post, could you pls. check my below e-mail & give me you
>confirmation.
>
>Thanks in advance.
>Nguyen Hoang Long
>
>----- Original Message -----
>From: "Nguyen Hoang Long" <ng-hlong@hn.vnn.vn>
>To: <ccielab@groupstudy.com>
>Sent: Tuesday, November 05, 2002 6:39 PM
>Subject: To correct DLSW NetBIOS filter
>
>
> > Hi all,
> >
> > As I understand, NetBIOS traffic uses SAP values 0xF0 (for commands) and
>0xF1
> > (for responses).
> > But that is for SSAP only, not DSAP.
> >
> > But in most of wel-known resources, to filter NetBIOS they use:
> > access-list 200 deny 0xF0F0 0x0101
> >
> > I think above ACL is redundant & does not make points in the LAB, it
>should
> > be narrowed to:
> > access-list 200 deny 0xF0F0 0x0001
> >
> > Expecting your comments.
> >
> > Thanks,
> > Nguyen Hoang Long



This archive was generated by hypermail 2.1.4 : Tue Dec 03 2002 - 07:22:54 GMT-3