Strane ACL Cisco 827 con IOS 12.1(1r)XB1
Inviato: dom 05 feb , 2006 10:52 am
Ciao belli...questo non è un reale problema ma un chiarimento...
Io ho creato tutte le mie belle ACL e le ho applicate alla dialer0 in entrata...tutto funziona però quando faccio uno sh access-l e da un pc in lan sto navigando o cmq sono in internet si visualizzano molte più acl di quelle che io ho inserito...
Dovrebbero essere delle acl "dinamiche" che si creano ad ogni sito visualizzato ma non le avevo mai viste prima...
E' una particolarità di questa ios? Si può disattivare questa funzione?
GRAZIE MILLE E BUON FINE SETTIMANA!!!
Extended IP access list 131
permit tcp host 62.85.163.47 eq www host 87.7.41.206 eq 1060 (8 matches)
permit tcp host 198.66.208.192 eq www host 87.7.41.206 eq 1068 (5 matches)
permit tcp host 198.66.208.192 eq www host 87.7.41.206 eq 1067 (7 matches)
permit tcp host 198.66.208.192 eq www host 87.7.41.206 eq 1063 (21 matches)
permit tcp host 198.66.208.192 eq www host 87.7.41.206 eq 1062 (40 matches)
permit tcp host 198.66.208.192 eq www host 87.7.41.206 eq 1058 (65 matches)
permit tcp host 64.233.183.104 eq www host 87.7.41.206 eq 1066 (12 matches)
permit tcp host 64.233.183.104 eq www host 87.7.41.206 eq 1065 (15 matches)
permit tcp host 64.233.183.99 eq www host 87.7.41.206 eq 1061 (5 matches)
permit tcp host 209.237.248.137 eq www host 87.7.41.206 eq 1064 (6 matches)
permit tcp host 67.19.167.98 eq www host 87.7.41.206 eq 1070 (4 matches)
permit tcp host 213.200.99.30 eq www host 87.7.41.206 eq 1034 (6 matches)
permit tcp host 213.242.94.33 eq www host 87.7.41.206 eq 1039 (6 matches)
permit tcp any any eq telnet (467 matches)
permit tcp any any eq 4652 (10 matches)
permit udp any any eq 4642 (634 matches)
permit tcp any any eq 4682 (135392 matches)
permit udp any any eq 4692 (6269 matches)
permit tcp any any eq 3389 (96 matches)
permit tcp any any eq 85 (66 matches)
deny ip 10.0.0.0 0.255.255.255 any log
deny ip 172.16.0.0 0.15.255.255 any log
deny ip 192.168.0.0 0.0.255.255 any log (2329 matches)
deny ip 127.0.0.0 0.255.255.255 any log
deny ip 224.0.0.0 31.255.255.255 any log
deny ip host 0.0.0.0 any log
permit tcp any any gt 1023 established (1759 matches)
permit udp any any gt 1023 (478 matches)
permit icmp any any echo (8 matches)
permit icmp any any echo-reply
permit icmp any any time-exceeded (24 matches)
permit icmp any any unreachable (712 matches)
permit icmp any any administratively-prohibited
permit icmp any any packet-too-big
permit icmp any any traceroute
deny icmp any any log (15 matches)
deny tcp any any eq 135 log (5872 matches)
deny udp any any eq 135 log
deny udp any any eq netbios-ns log (24 matches)
deny udp any any eq netbios-dgm log
deny tcp any any eq 139 log (1710 matches)
deny udp any any eq netbios-ss log
deny tcp any any eq 445 log (6672 matches)
deny tcp any any eq 593 log (14 matches)
deny udp any any eq 1433 log
deny udp any any eq 1434 log
deny ip any any dscp 1 log
deny udp any any eq 5554 log
deny udp any any eq 9996 log
deny udp any any eq 113 log
deny udp any any eq 3067 log
permit udp any host 151.99.125.2 eq domain
permit udp any host 151.99.125.1 eq domain
deny udp any any eq domain log (9 matches)
deny ip any any log (35499 matches)
Io ho creato tutte le mie belle ACL e le ho applicate alla dialer0 in entrata...tutto funziona però quando faccio uno sh access-l e da un pc in lan sto navigando o cmq sono in internet si visualizzano molte più acl di quelle che io ho inserito...
Dovrebbero essere delle acl "dinamiche" che si creano ad ogni sito visualizzato ma non le avevo mai viste prima...
E' una particolarità di questa ios? Si può disattivare questa funzione?
GRAZIE MILLE E BUON FINE SETTIMANA!!!
Extended IP access list 131
permit tcp host 62.85.163.47 eq www host 87.7.41.206 eq 1060 (8 matches)
permit tcp host 198.66.208.192 eq www host 87.7.41.206 eq 1068 (5 matches)
permit tcp host 198.66.208.192 eq www host 87.7.41.206 eq 1067 (7 matches)
permit tcp host 198.66.208.192 eq www host 87.7.41.206 eq 1063 (21 matches)
permit tcp host 198.66.208.192 eq www host 87.7.41.206 eq 1062 (40 matches)
permit tcp host 198.66.208.192 eq www host 87.7.41.206 eq 1058 (65 matches)
permit tcp host 64.233.183.104 eq www host 87.7.41.206 eq 1066 (12 matches)
permit tcp host 64.233.183.104 eq www host 87.7.41.206 eq 1065 (15 matches)
permit tcp host 64.233.183.99 eq www host 87.7.41.206 eq 1061 (5 matches)
permit tcp host 209.237.248.137 eq www host 87.7.41.206 eq 1064 (6 matches)
permit tcp host 67.19.167.98 eq www host 87.7.41.206 eq 1070 (4 matches)
permit tcp host 213.200.99.30 eq www host 87.7.41.206 eq 1034 (6 matches)
permit tcp host 213.242.94.33 eq www host 87.7.41.206 eq 1039 (6 matches)
permit tcp any any eq telnet (467 matches)
permit tcp any any eq 4652 (10 matches)
permit udp any any eq 4642 (634 matches)
permit tcp any any eq 4682 (135392 matches)
permit udp any any eq 4692 (6269 matches)
permit tcp any any eq 3389 (96 matches)
permit tcp any any eq 85 (66 matches)
deny ip 10.0.0.0 0.255.255.255 any log
deny ip 172.16.0.0 0.15.255.255 any log
deny ip 192.168.0.0 0.0.255.255 any log (2329 matches)
deny ip 127.0.0.0 0.255.255.255 any log
deny ip 224.0.0.0 31.255.255.255 any log
deny ip host 0.0.0.0 any log
permit tcp any any gt 1023 established (1759 matches)
permit udp any any gt 1023 (478 matches)
permit icmp any any echo (8 matches)
permit icmp any any echo-reply
permit icmp any any time-exceeded (24 matches)
permit icmp any any unreachable (712 matches)
permit icmp any any administratively-prohibited
permit icmp any any packet-too-big
permit icmp any any traceroute
deny icmp any any log (15 matches)
deny tcp any any eq 135 log (5872 matches)
deny udp any any eq 135 log
deny udp any any eq netbios-ns log (24 matches)
deny udp any any eq netbios-dgm log
deny tcp any any eq 139 log (1710 matches)
deny udp any any eq netbios-ss log
deny tcp any any eq 445 log (6672 matches)
deny tcp any any eq 593 log (14 matches)
deny udp any any eq 1433 log
deny udp any any eq 1434 log
deny ip any any dscp 1 log
deny udp any any eq 5554 log
deny udp any any eq 9996 log
deny udp any any eq 113 log
deny udp any any eq 3067 log
permit udp any host 151.99.125.2 eq domain
permit udp any host 151.99.125.1 eq domain
deny udp any any eq domain log (9 matches)
deny ip any any log (35499 matches)