Re: access-class out to prevent telnet

From: NaYyaR <nyrhh_at_hotmail.co.uk>
Date: Sun, 19 Apr 2009 06:30:57 +0100

Tried this and it appeared to work ...

100 deny tcp 0.0.0.0 0.0.0.0 141.0.0.0 0.255.255.255 eq 23

--------------------------------------------------
From: "Modular" <modulartx_at_gmail.com>
Sent: Sunday, April 19, 2009 5:41 AM
To: "Cisco certification" <ccielab_at_groupstudy.com>
Subject: access-class out to prevent telnet

> Has anyone here had success with preventing outbound telnet from a router
> using access-class out?
> According to this doc you should use a standard ACL and what would
> normally
> be considered the
> source would actually be the destination:
>
> http://www.cisco.com/en/US/docs/ios/security/configuration/guide/sec_cntrl_acc_vtl.html
>
> I tried this and no dice. I tried using an extended ACL:
>
> access-list 101 deny ip any any
>
> and no dice.
>
> No matter what I try... I can't seem to prevent outbound telnet from a
> router using
> access-class out.
>
> Thanks,
> Bryan R.
>
>
> Blogs and organic groups at http://www.ccie.net
>
> _______________________________________________________________________
> Subscription information may be found at:
> http://www.groupstudy.com/list/CCIELab.html

Blogs and organic groups at http://www.ccie.net
Received on Sun Apr 19 2009 - 06:30:57 ART

This archive was generated by hypermail 2.2.0 : Mon May 04 2009 - 07:39:12 ART