Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations SkipVought on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

access-list question 1

Status
Not open for further replies.

boymarty24

Technical User
Aug 21, 2003
362
0
0
SE
Hi!

Can someone give me a good explanation why you should use outbound access-lists instead of inbound.

Example.

I want to restrict inside users to only use http and https. As i understand you can use inbound on inside interface or/and outbound on outside interface. I have always used inbound on inside interface for this kind of configurations but found on ciscos homepage an example with outbound statement. I did not really understand why outbound was a better choice though.

Cheers

Marty
 
think of the user going 'outbound' on the inside interface, not to mention the inside interface has a higher level of security
 
The only use I have found for it would be blocking traffic from multiple higher security interfaces to a lower one.
I always restrict SMTP to servers that I know. So rather than placing that restriction on the inbound INSIDE, DMZ, and WIRELESS interfaces you can put it on the outbound OUTSIDE interface only once.

Now, I don't actually do this as I believe you should block unwanted traffic closest to the source. It's the low powered router guy in me who doesn't want to have unnecessary processing going on but with todays fun toys I don't think it is much of a problem unless you have a giant environment.

Brent
Systems Engineer / Consultant
CCNP, CCSP
 
Brent,

That makes sense! Thanks for you answers
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top