<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ACL allowing internal clients access to outside FTP data on cisc in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/acl-allowing-internal-clients-access-to-outside-ftp-data-on/m-p/2202102#M358844</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hey man my pleasure,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Remember to rate all of the helpful posts and can you mark the question as answered?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 05 Apr 2013 19:59:03 GMT</pubDate>
    <dc:creator>Julio Carvajal</dc:creator>
    <dc:date>2013-04-05T19:59:03Z</dc:date>
    <item>
      <title>ACL allowing internal clients access to outside FTP data on cisco 3750</title>
      <link>https://community.cisco.com/t5/network-security/acl-allowing-internal-clients-access-to-outside-ftp-data-on/m-p/2202097#M358839</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have this ACL on a cisco 3750 for allowing internal clients to access outside&amp;nbsp; FTP&amp;nbsp; servers, and I am concerned about the security hole that the last statement it might create:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list 111 permit tcp 10.100.111.0 0.0.0.255 gt 1023 any eq ftp&lt;/P&gt;&lt;P&gt;access-list 111 permit tcp 10.100.111.0 0.0.0.255 gt 1023 any eq ftp-data&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list 111 permit tcp 10.100.111.0 0.0.0.255 gt 1023 any gt 1023&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is the only way I could get internal clients to access FTP data outside&amp;nbsp; the network/Internet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The access-list is applied &lt;STRONG&gt;inbound&lt;/STRONG&gt; on the &lt;STRONG&gt;VLAN interface&lt;/STRONG&gt; on the 3750.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Will this expose clients to a security risk?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 01:24:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl-allowing-internal-clients-access-to-outside-ftp-data-on/m-p/2202097#M358839</guid>
      <dc:creator>iosepmonica</dc:creator>
      <dc:date>2019-03-12T01:24:12Z</dc:date>
    </item>
    <item>
      <title>ACL allowing internal clients access to outside FTP data on cisc</title>
      <link>https://community.cisco.com/t5/network-security/acl-allowing-internal-clients-access-to-outside-ftp-data-on/m-p/2202098#M358840</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So this is applied on the internal interface right?? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What FTP mode are you running, if it's passive where the client innitiates both connectionns Control and data channel then you must have it like that... I mean it will not expose as this is traffic from your clients to the outside, not from outside to inside.. You follow me&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Why don't you restrict traffic on the interface that is next to the outside world?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Apr 2013 18:19:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl-allowing-internal-clients-access-to-outside-ftp-data-on/m-p/2202098#M358840</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-04-05T18:19:40Z</dc:date>
    </item>
    <item>
      <title>ACL allowing internal clients access to outside FTP data on cisc</title>
      <link>https://community.cisco.com/t5/network-security/acl-allowing-internal-clients-access-to-outside-ftp-data-on/m-p/2202099#M358841</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Correct, this is applied on the internal interface, and it is for internal clients accessing FTP servers on the Internet mostly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In a typical environment, I would do this on a firewall, but in this particular case, this client wants it on the internal L3 switch. This switch has an interface that connects to a gateway for Internet access. &lt;/P&gt;&lt;P&gt;No connections initiated from outside to the internal clients are allowed at all, and the traffic going to the Internet only includes FTP, NTP and DNS.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Apr 2013 18:43:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl-allowing-internal-clients-access-to-outside-ftp-data-on/m-p/2202099#M358841</guid>
      <dc:creator>iosepmonica</dc:creator>
      <dc:date>2013-04-05T18:43:42Z</dc:date>
    </item>
    <item>
      <title>ACL allowing internal clients access to outside FTP data on cisc</title>
      <link>https://community.cisco.com/t5/network-security/acl-allowing-internal-clients-access-to-outside-ftp-data-on/m-p/2202100#M358842</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, so that would be the only way to make it happen as you will need some sort of inspection in order to open the right pinholes for the outgoing Data channel,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but if everything for out to in is being denied you should be good to go&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Remember to rate all of the helpful posts&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio Carvajal Segura&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Apr 2013 19:39:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl-allowing-internal-clients-access-to-outside-ftp-data-on/m-p/2202100#M358842</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-04-05T19:39:34Z</dc:date>
    </item>
    <item>
      <title>ACL allowing internal clients access to outside FTP data on cisc</title>
      <link>https://community.cisco.com/t5/network-security/acl-allowing-internal-clients-access-to-outside-ftp-data-on/m-p/2202101#M358843</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you very much!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Apr 2013 19:51:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl-allowing-internal-clients-access-to-outside-ftp-data-on/m-p/2202101#M358843</guid>
      <dc:creator>iosepmonica</dc:creator>
      <dc:date>2013-04-05T19:51:52Z</dc:date>
    </item>
    <item>
      <title>ACL allowing internal clients access to outside FTP data on cisc</title>
      <link>https://community.cisco.com/t5/network-security/acl-allowing-internal-clients-access-to-outside-ftp-data-on/m-p/2202102#M358844</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hey man my pleasure,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Remember to rate all of the helpful posts and can you mark the question as answered?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Apr 2013 19:59:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl-allowing-internal-clients-access-to-outside-ftp-data-on/m-p/2202102#M358844</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-04-05T19:59:03Z</dc:date>
    </item>
  </channel>
</rss>

