<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic WAN Inbound protection in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/wan-inbound-protection/m-p/2376114#M309316</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes but since having remote ipsec vpn should I exclude the allocated subnet range ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 08 Nov 2013 20:55:05 GMT</pubDate>
    <dc:creator>aconticisco</dc:creator>
    <dc:date>2013-11-08T20:55:05Z</dc:date>
    <item>
      <title>WAN Inbound protection</title>
      <link>https://community.cisco.com/t5/network-security/wan-inbound-protection/m-p/2376112#M309314</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;what is the best practice to protect the WAN Interface (Dialer Interface) on ISR Router from common attacks or ip spoofing. I read about creating an ACL to include all internal ip ranges but want to get your feedback on what is best to do. Also will need to allow remote ipsecvpn client to connect from remote.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank You&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 03:02:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/wan-inbound-protection/m-p/2376112#M309314</guid>
      <dc:creator>aconticisco</dc:creator>
      <dc:date>2019-03-12T03:02:08Z</dc:date>
    </item>
    <item>
      <title>WAN Inbound protection</title>
      <link>https://community.cisco.com/t5/network-security/wan-inbound-protection/m-p/2376113#M309315</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One common way to do it is to create an ACL denying traffic from the private IP address range comming on the outside interface.&lt;/P&gt;&lt;P&gt;Enabling IP RPF checks on strict mode is also a method to avoid this attacks as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How does that sounds to you&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rate all of the helpful posts!!! &lt;BR /&gt; &lt;BR /&gt;Regards, &lt;BR /&gt; &lt;BR /&gt;Jcarvaja &lt;BR /&gt; &lt;BR /&gt;&lt;SPAN&gt;Follow me on &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://laguiadelnetworking.com"&gt;http://laguiadelnetworking.com&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Nov 2013 00:11:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/wan-inbound-protection/m-p/2376113#M309315</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-11-08T00:11:22Z</dc:date>
    </item>
    <item>
      <title>WAN Inbound protection</title>
      <link>https://community.cisco.com/t5/network-security/wan-inbound-protection/m-p/2376114#M309316</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes but since having remote ipsec vpn should I exclude the allocated subnet range ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Nov 2013 20:55:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/wan-inbound-protection/m-p/2376114#M309316</guid>
      <dc:creator>aconticisco</dc:creator>
      <dc:date>2013-11-08T20:55:05Z</dc:date>
    </item>
    <item>
      <title>WAN Inbound protection</title>
      <link>https://community.cisco.com/t5/network-security/wan-inbound-protection/m-p/2376115#M309317</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Remember the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sysopt connection permit-vpn is enabled by default and will make VPN traffic to bypass any Inbound ACL on the outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;U got all set now right &lt;SPAN __jive_emoticon_name="grin" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/grin.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rate all of the helpful posts!!! &lt;BR /&gt; &lt;BR /&gt;Regards, &lt;BR /&gt; &lt;BR /&gt;Jcarvaja &lt;BR /&gt; &lt;BR /&gt;&lt;SPAN&gt;Follow me on &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://laguiadelnetworking.com"&gt;http://laguiadelnetworking.com&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 09 Nov 2013 00:10:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/wan-inbound-protection/m-p/2376115#M309317</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-11-09T00:10:38Z</dc:date>
    </item>
    <item>
      <title>WAN Inbound protection</title>
      <link>https://community.cisco.com/t5/network-security/wan-inbound-protection/m-p/2376116#M309318</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;seems that the command is not available on ISR Routers:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/products/ps6120/products_tech_note09186a00807e0aca.shtml#solution11" style="color: #2970a6; text-decoration: none; font-size: 12px; line-height: 13px;"&gt;Verify that sysopt Commands are Present (PIX/ASA Only)&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Command did not show up in ISR Syntax. Want to be sure of this before I apply the inbound ACL on the WAN Interface. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 09 Nov 2013 10:54:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/wan-inbound-protection/m-p/2376116#M309318</guid>
      <dc:creator>aconticisco</dc:creator>
      <dc:date>2013-11-09T10:54:27Z</dc:date>
    </item>
    <item>
      <title>WAN Inbound protection</title>
      <link>https://community.cisco.com/t5/network-security/wan-inbound-protection/m-p/2376117#M309319</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am sorry &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I though this was an ASA..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;in that case I would certanly permit that traffic in the Outside to Inside ACL &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rate all of the helpful posts!!! &lt;BR /&gt; &lt;BR /&gt;Regards, &lt;BR /&gt; &lt;BR /&gt;Jcarvaja &lt;BR /&gt; &lt;BR /&gt;&lt;SPAN&gt;Follow me on &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://laguiadelnetworking.com"&gt;http://laguiadelnetworking.com&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 10 Nov 2013 05:37:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/wan-inbound-protection/m-p/2376117#M309319</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-11-10T05:37:22Z</dc:date>
    </item>
  </channel>
</rss>

