[59714] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Protecting inbound interfaces (re: Cisco exploit)

daemon@ATHENA.MIT.EDU (Rick Ernst)
Fri Jul 18 09:08:34 2003

Date: Fri, 18 Jul 2003 06:07:08 -0700 (PDT)
From: Rick Ernst <ernst@easystreet.com>
To: nanog@merit.edu
Errors-To: owner-nanog-outgoing@merit.edu



Is there a way to globally protect all inbound interfaces on a router via ACL
(specifically hundreds of frame/sub-interfaces) without applying the same ACL
to each individual interface?

Is the "line vty" config only for telnet/ssh, etc. or is it the magic global
that I'm looking for?

I'd post this on inet-access but this is where the conversation is taking
place.

Thanks,
Rick





home help back first fref pref prev next nref lref last post