<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic CBAC: creating temporary entries in another interface? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cbac-creating-temporary-entries-in-another-interface/m-p/1877056#M460106</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Inside-----ROUTER------Outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So lets say you have an ACL on the outside interface denying all the inbound traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So if you add a CBAC inspection policy on the inside interface to inspect some traffic, that particular traffic being inspected will override the ACL ( that is why CISCO said it will create temporary entris on the inbound&amp;nbsp; ACL on the outside interface because even thoug you are denying all the traffic, that traffic will be accepted because of the IP inspect)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope I could help,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,!!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 06 Feb 2012 06:28:23 GMT</pubDate>
    <dc:creator>Julio Carvajal</dc:creator>
    <dc:date>2012-02-06T06:28:23Z</dc:date>
    <item>
      <title>CBAC: creating temporary entries in another interface?</title>
      <link>https://community.cisco.com/t5/network-security/cbac-creating-temporary-entries-in-another-interface/m-p/1877055#M460105</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am trying to understand the example at &lt;A href="http://www.cisco.com/en/US/docs/ios/sec_data_plane/configuration/guide/sec_cfg_content_ac.html#wp1002224" target="_blank"&gt;http://www.cisco.com/en/US/docs/ios/sec_data_plane/configuration/guide/sec_cfg_content_ac.html#wp1002224&lt;/A&gt; in which the "ip inspect" command is applied to Ethernet 1/0 but the document says that the dynamic temporary entries will be created in the ACL 100 which is applied to another interface (Etherent 1/1). Is this true? I am under the impression that "ip inspect ... in" will add entries to the outbound ACL for the same interface, while &lt;/P&gt;&lt;P&gt;"ip inspect ... out" will add entries to the inbound ACL for the same interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 22:24:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cbac-creating-temporary-entries-in-another-interface/m-p/1877055#M460105</guid>
      <dc:creator>freemant2000</dc:creator>
      <dc:date>2019-03-11T22:24:04Z</dc:date>
    </item>
    <item>
      <title>CBAC: creating temporary entries in another interface?</title>
      <link>https://community.cisco.com/t5/network-security/cbac-creating-temporary-entries-in-another-interface/m-p/1877056#M460106</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Inside-----ROUTER------Outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So lets say you have an ACL on the outside interface denying all the inbound traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So if you add a CBAC inspection policy on the inside interface to inspect some traffic, that particular traffic being inspected will override the ACL ( that is why CISCO said it will create temporary entris on the inbound&amp;nbsp; ACL on the outside interface because even thoug you are denying all the traffic, that traffic will be accepted because of the IP inspect)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope I could help,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,!!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Feb 2012 06:28:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cbac-creating-temporary-entries-in-another-interface/m-p/1877056#M460106</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-02-06T06:28:23Z</dc:date>
    </item>
    <item>
      <title>CBAC: creating temporary entries in another interface?</title>
      <link>https://community.cisco.com/t5/network-security/cbac-creating-temporary-entries-in-another-interface/m-p/1877057#M460107</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the reply! If the router has multiple interfaces, how can it determine which is the outside interface to add the temporary entries to?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Feb 2012 06:35:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cbac-creating-temporary-entries-in-another-interface/m-p/1877057#M460107</guid>
      <dc:creator>freemant2000</dc:creator>
      <dc:date>2012-02-06T06:35:47Z</dc:date>
    </item>
    <item>
      <title>CBAC: creating temporary entries in another interface?</title>
      <link>https://community.cisco.com/t5/network-security/cbac-creating-temporary-entries-in-another-interface/m-p/1877058#M460108</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ka, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It really depends on where you actually applied the Inspection to. Lets assume you have 3 interfaces, and you put the ip inspect in on the "inside interface" Cbac will assume that all of them are outside and if they all have acls applied inbound, no matter if it has a deny IP any any on all of them, the traffic will be allowed to come in.&amp;nbsp; But if the IP inspect is applied outbound on one interface, the traffic coming in is only going to be allowed on that specific interface, from whenever the traffic started from. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope this makes sense. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Feb 2012 16:26:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cbac-creating-temporary-entries-in-another-interface/m-p/1877058#M460108</guid>
      <dc:creator>Maykol Rojas</dc:creator>
      <dc:date>2012-02-06T16:26:26Z</dc:date>
    </item>
    <item>
      <title>CBAC: creating temporary entries in another interface?</title>
      <link>https://community.cisco.com/t5/network-security/cbac-creating-temporary-entries-in-another-interface/m-p/1877059#M460109</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I see. Thanks! Is there any documentation on this behavior? For the case where inspection is applied to an inside interface, the doc seems to say that we can have either an outbound ACL on that inside inferface or inbound ACL on the outside interface(s) for CBAC to add the temporary entries to. if both are present, I guess both will be added to?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Feb 2012 04:17:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cbac-creating-temporary-entries-in-another-interface/m-p/1877059#M460109</guid>
      <dc:creator>freemant2000</dc:creator>
      <dc:date>2012-02-07T04:17:04Z</dc:date>
    </item>
    <item>
      <title>CBAC: creating temporary entries in another interface?</title>
      <link>https://community.cisco.com/t5/network-security/cbac-creating-temporary-entries-in-another-interface/m-p/1877060#M460112</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Ka,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You do not need it, as soon as you have the inspection the returning traffic that matches the connections being inspected by CBAC will be allowed and will overwrite any ACL denying that traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think its a way to see things because as an example:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Inside------Router----Outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Lets say you have an ACL denying all traffic on the outside interface inbound direction, with CBAC configure on the inside for outbound TCP connections, all the TCP traffic returning for a connection that matches the traffic being inspected will be allowed ( so yes a temporary entry will be added to the inbound ACL on the outside interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That is the whole purpose of CBAC ( A stateful firewall)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Feb 2012 05:30:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cbac-creating-temporary-entries-in-another-interface/m-p/1877060#M460112</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-02-07T05:30:05Z</dc:date>
    </item>
    <item>
      <title>CBAC: creating temporary entries in another interface?</title>
      <link>https://community.cisco.com/t5/network-security/cbac-creating-temporary-entries-in-another-interface/m-p/1877061#M460117</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Pretty much yes, the only thing you need to make sure is that there is an allow in order for the traffic to be inspected. The return traffic should not be blocked as the session is already up. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is a good doc: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/products/sw/secursw/ps1018/products_tech_note09186a0080094e8b.shtml"&gt;http://www.cisco.com/en/US/products/sw/secursw/ps1018/products_tech_note09186a0080094e8b.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Feb 2012 14:34:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cbac-creating-temporary-entries-in-another-interface/m-p/1877061#M460117</guid>
      <dc:creator>Maykol Rojas</dc:creator>
      <dc:date>2012-02-07T14:34:12Z</dc:date>
    </item>
  </channel>
</rss>

