RE: [fw-wiz] Cisco acls

From: Luke Butcher (Luke.Butcher_at_alphawest.com.au)
Date: 03/30/05

  • Next message: Rob Hughes: "Re: [fw-wiz] Site-to-Site VPN Gateway behind NAT device"
    To: "Scott Stursa" <stursa@mailer.fsu.edu>
    Date: Wed, 30 Mar 2005 08:29:19 +1000
    
    

     
    From: Scott Stursa
    Sent: Friday, 25 March 2005 4:54 AM

    >> On Tue, 15 Mar 2005, Luke Butcher wrote:

    >> Not sure about a lint checker and router ACLs unfortunately don't
    show a hit count like PIX ones.

    > Yes they do.

    > The only place I've seen "missed" hits are on switches doing VLAN
    switching. Although the initial handshake will
    > generate hits, once it goes into switching mode the ACL will never see
    the packets. The difference is clear if you
    > have an ACL which begins with "permit tcp any any established"; on a
    non-switched interface this line will show the > greatest number of hits
    in the ACL, on a switched one it will show the lowest.

    Sorry I meant in the way a PIX displays 'hitcnt=' right next to the line
    when you do a show access-list. This makes it very easy to tell what
    lines are being used and which ones aren't.

    Regards,
    Luke Butcher
    Network/Security Consultant
    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  • Next message: Rob Hughes: "Re: [fw-wiz] Site-to-Site VPN Gateway behind NAT device"

    Relevant Pages

    • RE: [fw-wiz] Cisco acls
      ... The only place I've seen "missed" hits are on switches doing VLAN ... into switching mode the ACL will never see the packets. ... ACL logging is rate limited; only a percentage of the matches will be ...
      (Firewall-Wizards)
    • RE: [fw-wiz] Cisco acls
      ... show any hits at all on ACL entries. ... and up shows hits on both routing policy acl's and interface acl's. ... once it goes into switching mode the ACL will never see ... If you are not the intended recipient please notify the sender ...
      (Firewall-Wizards)
    • Re: Brad and Angelina baby photos -- a question...
      ... Post printing these pix BEFORE People hits the stands? ... strike me as much of an exclusive, ...
      (rec.arts.movies.current-films)
    • Re: FIREWALL VPN ADSL
      ... Show them how easy it it using the PIX, start with switching to bridge mode ... on the ADSL-Router. ...
      (comp.dcom.sys.cisco)
    • Re: Can anyone recommend a good VPN appliance?
      ... Your best options are to consider either switching out the ... > Pix with something else, ... Lars: Don't get a swelled head, but I like the way you think:) ...
      (comp.security.firewalls)