of course at the end there is a implicit deny but I always place an:
access-list 120 deny ip any any log
The extended access list can be configured any way you would like. If you give me a little further information on what you want I can help you out. Give me a sample packet path from host to host.
Hi.
I want to ban ICMP replay for incoming packets matching 'deny' entries in access-list without addtion corresponding ICMP entries in outcoming access-list.
This will deny ICMP from anyone AND surpress the echo reponse that normally go out saying it had been surpressed. There are a few options regarding the echo replies. This goes to the incoming list without any changes to the outgoing lists.
Mike S
"Diplomacy; the art of saying 'nice doggie' till you can find a rock" Wynn Catlin
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.