Allora, l'ho fatto anche da me qua a lavoro. Praticamente questa era l'access list prima dell'ip inspect:
Codice: Seleziona tutto
access-list 100 remark *** ACL ANTI-SPOOFING ***
access-list 100 deny ip host 0.0.0.0 any log
access-list 100 deny ip host 255.255.255.255 any
access-list 100 deny ip 127.0.0.0 0.255.255.255 any log
access-list 100 deny ip 192.0.2.0 0.0.0.255 any log
access-list 100 deny ip 224.0.0.0 31.255.255.255 any log
access-list 100 deny ip 10.0.0.0 0.255.255.255 any log
access-list 100 deny ip 172.16.0.0 0.15.255.255 any log
access-list 100 deny ip 192.168.0.0 0.0.255.255 any log
access-list 100 remark *** ACL PER CONTROLLARE TRAFFICO DNS ***
access-list 100 permit udp host 151.99.125.2 eq domain any
access-list 100 permit udp host 151.99.0.100 eq domain any
access-list 100 permit udp host 212.216.112.112 eq domain any
access-list 100 remark *** ACL PER CONTROLLARE NO-IP ***
access-list 100 permit tcp host 204.16.252.79 eq www any
access-list 100 remark *** ACL PER CONTROLLARE TRAFFICO NTP ***
access-list 100 permit udp host 193.204.114.233 eq ntp any eq ntp
access-list 100 permit udp host 193.204.114.232 eq ntp any eq ntp
access-list 100 remark *** ACL PER APPLICAZIONI SERVER ***
access-list 100 permit tcp any any eq 3389
access-list 100 permit tcp any any eq ftp
access-list 100 permit tcp any any eq www
access-list 100 permit tcp any any eq 8080
access-list 100 permit tcp any any eq 143
access-list 100 permit tcp any any eq 443
access-list 100 remark *** ACL PER VPN ***
access-list 100 permit tcp any any eq 1723
access-list 100 permit udp any eq isakmp any eq isakmp
access-list 100 permit gre any any
access-list 100 remark *** ACL PER CONTROLLARE TRAFFICO ICMP ***
access-list 100 permit icmp any any echo-reply
access-list 100 permit icmp any any time-exceeded
access-list 100 permit icmp any any unreachable
access-list 100 permit icmp any any administratively-prohibited
access-list 100 permit icmp any any packet-too-big
access-list 100 permit icmp any any traceroute
access-list 100 deny icmp any any
access-list 100 remark *** ACL PER BLOCCARE ACCESSI ***
access-list 100 deny ip any any
Invece questa è l'acl dopo l'intervento:
Codice: Seleziona tutto
access-list 100 remark *** ACL ANTI-SPOOFING ***
access-list 100 deny ip host 0.0.0.0 any log
access-list 100 deny ip host 255.255.255.255 any
access-list 100 deny ip 127.0.0.0 0.255.255.255 any log
access-list 100 deny ip 192.0.2.0 0.0.0.255 any log
access-list 100 deny ip 224.0.0.0 31.255.255.255 any log
access-list 100 deny ip 10.0.0.0 0.255.255.255 any log
access-list 100 deny ip 172.16.0.0 0.15.255.255 any log
access-list 100 deny ip 192.168.0.0 0.0.255.255 any log
access-list 100 remark *** ACL PER APPLICAZIONI SERVER ***
access-list 100 permit tcp any any eq 3389
access-list 100 permit tcp any any eq ftp
access-list 100 permit tcp any any eq www
access-list 100 permit tcp any any eq 8080
access-list 100 permit tcp any any eq 143
access-list 100 permit tcp any any eq 443
access-list 100 remark *** ACL PER VPN ***
access-list 100 permit tcp any any eq 1723
access-list 100 permit udp any eq isakmp any eq isakmp
access-list 100 permit gre any any
access-list 100 remark *** ACL PER BLOCCARE ACCESSI ***
access-list 100 deny ip any any
Molto piu', snella, vero?
Questa è la mia attuale config dell'ip inspect
Codice: Seleziona tutto
ip inspect max-incomplete low 250
ip inspect max-incomplete high 300
ip inspect one-minute low 300
ip inspect one-minute high 400
ip inspect hashtable-size 2048
ip inspect tcp synwait-time 20
ip inspect tcp max-incomplete host 300 block-time 60
ip inspect name inspection-out tcp router-traffic
ip inspect name inspection-out udp router-traffic
ip inspect name inspection-out ftp
ip inspect name inspection-out https
ip inspect name inspection-out dns
ip inspect name inspection-out ntp
ip inspect name inspection-out icmp router-traffic
ip inspect name inspection-out bittorrent
ip inspect name inspection-out edonkey
ip inspect name inspection-out http java-list 50
ip inspect name inspection-out imap
ip inspect name inspection-out irc
ip inspect name inspection-out l2tp
ip inspect name inspection-out pptp
ip inspect name inspection-out pop3
ip inspect name inspection-out smtp
ip inspect name inspection-out telnet
ip inspect name inspection-in http
ip inspect name inspection-in https
ip inspect name inspection-in imap
ip inspect name inspection-in ftp
Codice: Seleziona tutto
interface ATM0.1 point-to-point
ip inspect inspection-in in
ip inspect inspection-out out
Codice: Seleziona tutto
access-list 50 remark Permette java nel CBAC
access-list 50 permit any