04-01-2014 08:07 PM - edited 03-11-2019 09:01 PM
Hi Everyone,
I need to create ACL from source user subnet say 172.25.7.X to Destination subnet of server 192.168.50.X
i checked that traffic flow it goes via firewall 1
Source Interface of Firewall 1 when user traffic flow is X and goes to server 192.168.50.1 via firewall 1
interface Y.
So if i need to open the ACL to allow CIFS traffic from user PC to server i can open it under interface X where i use user PC subnet as source and server
subnet as destination i am ok with this.
Need to know for return traffic from server to PC via firewall interface Y to X do i need acl there also?
Regards
Mahesh
Solved! Go to Solution.
04-02-2014 04:02 AM
Hi Mahesh,
Until unless you generate a traffic that is initiated from server to PC... you do not need any ACL...
Becoz firewall does the stateful packet filtering and it will automatically allow the return traffic with identified value of the sequence number... But in case of icmp or something u need to allow specific on both outgoing and incoming interfaces.....
hope this helps.
04-02-2014 04:02 AM
Hi Mahesh,
Until unless you generate a traffic that is initiated from server to PC... you do not need any ACL...
Becoz firewall does the stateful packet filtering and it will automatically allow the return traffic with identified value of the sequence number... But in case of icmp or something u need to allow specific on both outgoing and incoming interfaces.....
hope this helps.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide