Lammle.com
  • Instructor-Led Training
    • Browse by Course
      • All Courses
      • CompTIA Courses
      • CiscoŽ Courses
      • Microsoft Courses
      • Wireless Courses
      • IT & Security Courses
      • Attend Online
    • Browse by Date
    • Browse by City
    • Deals and Discounts
      • Spring Specials
      • From CCENT to CCNA in 2 Weeks
      • From CCNA to CCNP in 3 Weeks
      • Corporate Solutions
      • Government Solutions
        • Government Solutions
        • GSA Pricing
      • Recent Newsletters
    • Corporate Solutions
    • Government Solutions
      • Government Solutions
      • GSA Pricing
    • Testimonials
    • Internetworking Salary Survey
  • Locations
    • Atlanta
    • Austin
    • Chicago
    • Dallas/Fort Worth
    • Denver
    • Durham
    • Glendale
    • Houston
    • Live Online Only
    • Los Angeles
    • New Hampshire
    • New York
    • Orlando
    • Raleigh
    • San Diego
    • San Francisco
    • Santa Rosa
    • Washington D.C.
    • England
    • Germany
    Locations
  • Self-Paced Learning
    • Online Live Training
    • E-Learning
    • Online CCNA Video Training
    • Practice Questions
    • DVD and Audio (Lammle Press)
    • Books
  • Blog
  • Forum
  • GlobalNet Consulting
    • Overview
    • Experience
    • Our Team
    • Methodology
    • Projects
    • Contact Us
  • About
    • About Todd Lammle
    • About GlobalNet Training & Consulting
      • About GlobalNet Consulting
    • Student Complaint Policy
    • Terms of Service
      • Privacy Policy
      • Why was my account disabled?
  • Contact
    • Feedback Form
    • Site Map
Home Forum

Official Lammle User Forum


Go Back   Lammle Forum > Cisco® CCSP > Securing Network Devices
Reload this Page SNRS Quick Reference Guide problem
Register FAQ Members List Social Groups Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Display Modes
Prev Previous Post   Next Post Next
  #1  
Old 09-10-2009, 10:29 AM
gabrielshorn gabrielshorn is offline
Senior Member
 
Join Date: Jul 2008
Posts: 211
Default SNRS Quick Reference Guide problem

Reading through the Cisco Press SNRS Quick Reference -- current one -- I have a problem with page 20. They're talking about how to configure CBAC with an ACL to block inbound traffic while applying "inspect" rules to the inside interface. They're obviously demonstrating the rule that says "put your rulesets closest to the source of the traffic." But it seems wrong.

They create an ACL that says:

access-list 100 deny ip any any

Then they create this inspect set:

ip inspect name MYFW tcp
ip inspect name MYFW udp
ip inspect name MYFW icmp

It breaks down here. They apply the ACL to the untrusted interface this way:

ip access-group 100 out

And the inspect ruleset to the trusted LAN interface:

ip inspect MYFW out

Shouldn't both of these rules end with "in"? That would put them closest to the traffic they're designed to filter. Interestingly, SDM seems to like to put the inspect ruleset on the outside interface inspecting outbound.

I guess I know my way is correct. I'm more wondering if there's any sense whatsoever in doing it according to the book or is this just another huge typo?
Reply With Quote
gabrielshorn
View Public Profile
Send a private message to gabrielshorn
Find all posts by gabrielshorn
 

Bookmarks
  • Submit Thread to Digg Digg
  • Submit Thread to del.icio.us del.icio.us
  • Submit Thread to StumbleUpon StumbleUpon
  • Submit Thread to Google Google
Thread Tools
Show Printable Version Show Printable Version
Email this Page Email this Page
Display Modes
Linear Mode Switch to Linear Mode
Hybrid Mode Switch to Hybrid Mode
Threaded Mode Threaded Mode

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Rules
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
BSCI Study guide Nicholas Routing 3 12-28-2009 09:32 AM
quick study guide for CCNA naymyowin Hiring (Jobs and Projects) 1 11-25-2009 06:59 AM
Subnetting Quick Ref. Guide aguilera Routing 0 07-16-2007 09:39 AM


All times are GMT -5. The time now is 12:53 PM.

Contact Us - Lammle.com - Archive - Top

Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2013, vBulletin Solutions, Inc.

CCDA, CCDP, CCIE, CCIP, CCNA, CCNP, Cisco, Cisco IOS, Cisco Systems, the Cisco Systems logo, and Networking Academy are registered trademarks or trademarks of Cisco Systems, Inc. and/or its affiliates in the U.S. and certain other countries. All other trademarks mentioned in this document or Web site are the property of their respective owners. The content of this website is the copyrighted property of Lammle.com.
© 2013 Lammle.comPrivacy Policy