Reflexive Access list

From: Kaiser Anwar (kaiseranwar@sbcglobal.net)
Date: Wed Jan 07 2004 - 11:42:57 GMT-3


HI,
 I was testing a reflexive access in the practice lab.It seems to be working.
But I wanted to be sure.
 here is the config. this is the understating I have for this that any traffic
that goes out with reflect keyword it has to exist in outside access-list
state table.
 Thanks in advance for your help.

 ip access-list extended inside
 permit ip any any reflect outbound

 ip access-list extended outside
 evaluate outbound
 permit ospf any any reflect inbound
 permit udp any any reflect inbound
 permit tcp any any reflect inbound

Kaiser Anwar



This archive was generated by hypermail 2.1.4 : Mon Feb 02 2004 - 09:07:37 GMT-3