Chapter 19: Access Control List Configuration Guide

you would have to create an ACL to allow responses from each specific outside host. If the number of outside hosts that internal users need to access is large or changes frequently, this can be difficult to maintain.

To address this problem, the SSR can be configured to accept outside TCP responses into the internal network, provided that the TCP connection was initiated internally. Otherwise, it will be rejected. To do this, enter the following command in Configure Mode:

Allow TCP responses from external hosts, provided the connection was established internally.

acl <name> permit tcp established

Note: The ports that are associated with the interface to which the ACL is applied must reside on updated SSR hardware. Please refer to Appendix A for details.

The following ACL illustrates this feature:

acl 101 permit tcp established acl 101 apply interface int1 input

Any incoming TCP packet on interface int1 is examined, and if the packet is in response to an internal request, it is permitted; otherwise, it is rejected. Note that the ACL contains no restriction for outgoing packets on interface int1, since internal hosts are allowed to access the outside world.

Creating and Modifying ACLs

The SSR provides two mechanisms for creating and modifying ACLs:

Editing ACLs on a remote host and uploading them to to the SSR using TFTP or RCP

Using the SSR’s ACL Editor

The following sections describe these methods.

Editing ACLs Offline

You can create and edit ACLs on a remote host and then upload them to the SSR with TFTP or RCP. With this method, you use a text editor on a remote host to edit, delete, replace, or reorder ACL rules in a file. Once the changes are made, you can then upload the ACLs to the SSR using TFTP or RCP and make them take effect on the running system. The following example describes how you can use TFTP to help maintain ACLs on the SSR.

264

SmartSwitch Router User Reference Manual

Page 290
Image 290
Cabletron Systems 9032578-05 Creating and Modifying ACLs, Editing ACLs Offline, Following ACL illustrates this feature