Codice: Seleziona tutto
access-list 131 remark #############################################
access-list 131 remark ACC-GROUP IN
access-list 131 remark **VPN**
access-list 131 permit gre any any
access-list 131 permit esp any any
access-list 131 permit udp any any eq isakmp
access-list 131 permit udp any any eq non500-isakmp
access-list 131 permit udp any eq isakmp any
access-list 131 permit udp any eq non500-isakmp any
access-list 131 remark **NTP**
access-list 131 permit udp host 193.204.114.232 any eq ntp
access-list 131 permit udp host 193.204.114.233 any eq ntp
access-list 131 remark **DNS**
access-list 131 permit udp host 208.67.222.222 any eq domain
access-list 131 permit udp host 208.67.220.220 any eq domain
access-list 131 permit udp host 151.99.125.1 any eq domain
access-list 131 permit udp host 151.99.250.2 any eq domain
access-list 131 permit udp host 88.149.128.20 any eq domain
access-list 131 permit udp host 212.216.112.112 any eq domain
access-list 131 remark **ANTI-SPOOFING**
access-list 131 deny ip host 0.0.0.0 any log
access-list 131 deny ip 127.0.0.0 0.255.255.255 any log
access-list 131 deny ip 192.0.2.0 0.0.0.255 any log
access-list 131 deny ip 224.0.0.0 31.255.255.255 any log
access-list 131 deny ip 10.0.0.0 0.255.255.255 any log
access-list 131 deny ip 172.16.0.0 0.15.255.255 any log
access-list 131 deny ip 192.168.0.0 0.0.255.255 any log
access-list 131 remark **ICMP**
access-list 131 permit icmp any any echo
access-list 131 permit icmp any any echo-reply
access-list 131 permit icmp any any time-exceeded
access-list 131 permit icmp any any unreachable
access-list 131 permit icmp any any administratively-prohibited
access-list 131 permit icmp any any packet-too-big
access-list 131 permit icmp any any traceroute
access-list 131 deny icmp any any
access-list 131 remark **WORM**
access-list 131 deny tcp any any eq 135
access-list 131 deny udp any any eq 135
access-list 131 deny udp any any eq netbios-ns
access-list 131 deny udp any any eq netbios-dgm
access-list 131 deny tcp any any eq 139
access-list 131 deny udp any any eq netbios-ss
access-list 131 deny tcp any any eq 445
access-list 131 deny tcp any any eq 8888
access-list 131 deny tcp any any eq 8594
access-list 131 deny tcp any any eq 8563
access-list 131 deny tcp any any eq 7778
access-list 131 deny tcp any any eq 593
access-list 131 deny tcp any any eq 2049
access-list 131 deny udp any any eq 2049
access-list 131 deny tcp any any eq 2000
access-list 131 deny tcp any any range 6000 6010
access-list 131 deny udp any any eq 1433
access-list 131 deny udp any any eq 1434
access-list 131 deny udp any any eq 5554
access-list 131 deny udp any any eq 9996
access-list 131 deny udp any any eq 113
access-list 131 deny udp any any eq 3067
access-list 131 remark **ALL**
access-list 131 deny ip any any log
Codice: Seleziona tutto
ip inspect name FW tcp
ip inspect name FW udp
ip inspect name FW icmp
Codice: Seleziona tutto
router#ping google.it
Translating "google.it"...domain server (151.99.125.1) (151.99.250.2) (208.67.222.222) (212.216.112.112) (88.149.128.20)
% Unrecognized host or address, or protocol not running.
Codice: Seleziona tutto
001318: .Oct 21 00:02:59.203 ROMA: %SEC-6-IPACCESSLOGP: list 131 denied udp 151.99.125.1(53) -> 80.183.224.164(58559), 2 packets
001319: .Oct 21 00:02:59.203 ROMA: %SEC-6-IPACCESSLOGP: list 131 denied udp 151.99.250.2(53) -> 80.183.224.164(53022), 2 packets
001320: .Oct 21 00:03:59.204 ROMA: %SEC-6-IPACCESSLOGP: list 131 denied udp 208.67.222.222(53) -> 80.183.224.164(51500), 2 packets
001324: .Oct 21 00:08:11.898 ROMA: %SEC-6-IPACCESSLOGP: list 131 denied udp 151.99.125.1(53) -> 80.183.224.164(57802), 1 packet
001326: .Oct 21 00:08:20.914 ROMA: %SEC-6-IPACCESSLOGP: list 131 denied udp 151.99.250.2(53) -> 80.183.224.164(51049), 1 packet
001328: .Oct 21 00:08:38.935 ROMA: %SEC-6-IPACCESSLOGP: list 131 denied udp 212.216.112.112(53) -> 80.183.224.164(50742), 1 packet
Codice: Seleziona tutto
zot@zotnbk:~$ ping google.it
PING google.it (72.14.221.104) 56(84) bytes of data.
64 bytes from fg-in-f104.google.com (72.14.221.104): icmp_seq=1 ttl=242 time=71.2 ms
64 bytes from fg-in-f104.google.com (72.14.221.104): icmp_seq=2 ttl=242 time=68.8 ms
64 bytes from fg-in-f104.google.com (72.14.221.104): icmp_seq=3 ttl=242 time=66.9 ms
64 bytes from fg-in-f104.google.com (72.14.221.104): icmp_seq=4 ttl=242 time=66.9 ms
64 bytes from fg-in-f104.google.com (72.14.221.104): icmp_seq=5 ttl=242 time=69.4 ms
64 bytes from fg-in-f104.google.com (72.14.221.104): icmp_seq=6 ttl=242 time=69.2 ms
Codice: Seleziona tutto
001307: .Oct 20 23:54:59.198 ROMA: %SEC-6-IPACCESSLOGP: list 131 denied udp 83.211.227.21(5060) -> 80.183.224.164(1176), 55 packets
001316: .Oct 20 23:59:59.201 ROMA: %SEC-6-IPACCESSLOGP: list 131 denied udp 83.211.227.21(5060) -> 80.183.224.164(1176), 11 packets