Hi all,
In one of our routers 192.168.X.X (a 1700 with IOS 12.0(7)T)that's connecting in one serial subinterface with another cisco 10.40.X.X(a 2600 with IOS 12.0(2)XD1) i recently add the following ACL:
access-list deny tcp any any eq 69
access-list deny udp any any eq 69
access-list deny tcp any any eq 3127
access-list deny tcp any any eq 3198
access-list permit ip any any
The idea was to block Blaster's propagation (port 69) and MyDoom's trojan listening; but from my 1700 i could'n see the 2600, in the sh frame pvc everything seemed OK, but the people on the other side we unable to connect to one of out servers. Removing the recently added ACL was the solution...i don't know why this happened, any ideas?
Regards,
In one of our routers 192.168.X.X (a 1700 with IOS 12.0(7)T)that's connecting in one serial subinterface with another cisco 10.40.X.X(a 2600 with IOS 12.0(2)XD1) i recently add the following ACL:
access-list deny tcp any any eq 69
access-list deny udp any any eq 69
access-list deny tcp any any eq 3127
access-list deny tcp any any eq 3198
access-list permit ip any any
The idea was to block Blaster's propagation (port 69) and MyDoom's trojan listening; but from my 1700 i could'n see the 2600, in the sh frame pvc everything seemed OK, but the people on the other side we unable to connect to one of out servers. Removing the recently added ACL was the solution...i don't know why this happened, any ideas?
Regards,