ACL for FTP

From: Alec (clapun@graduate.hku.hk)
Date: Sun Aug 24 2003 - 12:40:18 GMT-3


Hi group,

To restrict FTP traffic, besides port 21, do I need to explicitly allow
other port range for FTP DATA streams ?

access-list 101 permit tcp any any eq eq ftp
access-list 101 permit tcp any any gt 1023 <=== required ?
int e0
  ip access-group 101 in

regards,
alec



This archive was generated by hypermail 2.1.4 : Tue Sep 02 2003 - 18:54:05 GMT-3