<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic BGP shold be using tcp/179 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/iacl-usage/m-p/3027876#M907985</link>
    <description>&lt;P&gt;BGP should be using tcp/179 and I would expect&amp;nbsp;the neighbor relationship to be unaffected.&lt;/P&gt;
&lt;P&gt;I would however change the last line to "20 permit ip any any". Otherwise you will be blocking udp and icmp implicitly.&lt;/P&gt;</description>
    <pubDate>Wed, 03 May 2017 05:28:29 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2017-05-03T05:28:29Z</dc:date>
    <item>
      <title>iACL Usage</title>
      <link>https://community.cisco.com/t5/network-security/iacl-usage/m-p/3027875#M907984</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;We have a NX7K with two connections(e5/9 and e6/9) to our ISP. We use eBGP peering the two interfaces with the ISP. We tried to implement an iACL to deny ssh and snmp ingress traffic from out ISP to the NX7K but after implementing the iACL we experienced an Internet outage. It seems that the implementation of this iACLs broke the BGP peering for some reason. Here's the iACL we implemented:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;IP access list DENY_ACCESS&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; statistics per-entry&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10 deny tcp any any eq 22 log&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 15 deny udp any any eq snmp log&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 20 permit tcp any any&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;interface Ethernet5/9&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;ip access-group DENY_ACCESS in&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;exit&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;interface Ethernet6/9&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;ip access-group DENY_ACCESS in&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;exit&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&lt;SPAN style="font-size: 12pt;"&gt;Can anyone see why this iACL &amp;nbsp;would cause the bgp peering to break?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&lt;SPAN style="font-size: 12pt;"&gt;Thanks in advance.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&lt;SPAN style="font-size: 12pt;"&gt;~zK&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 14:04:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/iacl-usage/m-p/3027875#M907984</guid>
      <dc:creator>zekebashi</dc:creator>
      <dc:date>2020-02-21T14:04:18Z</dc:date>
    </item>
    <item>
      <title>BGP shold be using tcp/179</title>
      <link>https://community.cisco.com/t5/network-security/iacl-usage/m-p/3027876#M907985</link>
      <description>&lt;P&gt;BGP should be using tcp/179 and I would expect&amp;nbsp;the neighbor relationship to be unaffected.&lt;/P&gt;
&lt;P&gt;I would however change the last line to "20 permit ip any any". Otherwise you will be blocking udp and icmp implicitly.&lt;/P&gt;</description>
      <pubDate>Wed, 03 May 2017 05:28:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/iacl-usage/m-p/3027876#M907985</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-05-03T05:28:29Z</dc:date>
    </item>
    <item>
      <title>Thanks, Marvin! </title>
      <link>https://community.cisco.com/t5/network-security/iacl-usage/m-p/3027877#M907986</link>
      <description>&lt;P&gt;Thanks, Marvin!&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes, tcp 179 is allowed in this case and so bgp ingress traffic should be allowed. I'm &amp;nbsp;still puzzled by why bgp was affected by this iAC and still researching to find answer.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;I'll change statement "20", good idea!&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks, ~zK&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 May 2017 14:31:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/iacl-usage/m-p/3027877#M907986</guid>
      <dc:creator>zekebashi</dc:creator>
      <dc:date>2017-05-03T14:31:02Z</dc:date>
    </item>
    <item>
      <title>Are you sure that BGP was</title>
      <link>https://community.cisco.com/t5/network-security/iacl-usage/m-p/3027878#M907987</link>
      <description>&lt;P&gt;Are you sure that BGP was affected? Based on what you have told us so far your access list would not have allowed DNS packets. And if DNS is not working then your users would report that Internet access is broken. It might feel like there was a routing problem such as BGP not working. But the issue is DNS and not routing.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;HTH&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Rick&lt;/P&gt;</description>
      <pubDate>Thu, 04 May 2017 15:09:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/iacl-usage/m-p/3027878#M907987</guid>
      <dc:creator>Richard Burts</dc:creator>
      <dc:date>2017-05-04T15:09:09Z</dc:date>
    </item>
    <item>
      <title>Hi Rick, </title>
      <link>https://community.cisco.com/t5/network-security/iacl-usage/m-p/3027879#M907988</link>
      <description>&lt;P&gt;Hi Rick,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Sorry for the delayed response. I honestly don't think that the BGP peering dropped because when I checked the bgp neighbor status the connection status "drop" didn't show that the connection dropped.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I see what you're saying. So, since the ACL is denying udp services, DNS/UDP is being denied and that's why we experienced the Internet outage? Is that an accurate analysis?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Best, ~zK&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 May 2017 18:27:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/iacl-usage/m-p/3027879#M907988</guid>
      <dc:creator>zekebashi</dc:creator>
      <dc:date>2017-05-11T18:27:58Z</dc:date>
    </item>
    <item>
      <title>Yes that is an accurate</title>
      <link>https://community.cisco.com/t5/network-security/iacl-usage/m-p/3027880#M907989</link>
      <description>&lt;P&gt;Yes that is an accurate analysis.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;HTH&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Rick&lt;/P&gt;</description>
      <pubDate>Thu, 11 May 2017 18:36:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/iacl-usage/m-p/3027880#M907989</guid>
      <dc:creator>Richard Burts</dc:creator>
      <dc:date>2017-05-11T18:36:03Z</dc:date>
    </item>
    <item>
      <title>Thanks much, Rick! </title>
      <link>https://community.cisco.com/t5/network-security/iacl-usage/m-p/3027881#M907990</link>
      <description>&lt;P&gt;Thanks much, Rick!&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Best, ~sK&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 May 2017 18:41:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/iacl-usage/m-p/3027881#M907990</guid>
      <dc:creator>zekebashi</dc:creator>
      <dc:date>2017-05-11T18:41:15Z</dc:date>
    </item>
    <item>
      <title>You are welcome. I am glad</title>
      <link>https://community.cisco.com/t5/network-security/iacl-usage/m-p/3027882#M907991</link>
      <description>&lt;P&gt;You are welcome. I am glad that our answers have been helpful.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;HTH&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Rick&lt;/P&gt;</description>
      <pubDate>Thu, 11 May 2017 18:48:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/iacl-usage/m-p/3027882#M907991</guid>
      <dc:creator>Richard Burts</dc:creator>
      <dc:date>2017-05-11T18:48:42Z</dc:date>
    </item>
  </channel>
</rss>

