cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
553
Views
0
Helpful
1
Replies

Creating ACL for CIFS port from Source to Destination

mahesh18
Level 6
Level 6

 

Hi Everyone,

 

I need to create ACL from source user subnet say 172.25.7.X  to Destination subnet of server 192.168.50.X

i checked that traffic flow it  goes via firewall 1

 

Source Interface of Firewall 1 when user traffic flow  is X  and goes to server 192.168.50.1 via firewall 1

interface Y.

 

So if i need to open the ACL to allow CIFS traffic  from user PC  to server i can open it under interface X  where i use user PC subnet as source and server

subnet as destination i am ok with this.

 

Need to know for return traffic from server to PC via  firewall interface Y  to X  do i need acl there also?

Regards

 

Mahesh

1 Accepted Solution

Accepted Solutions

nkarthikeyan
Level 7
Level 7

Hi Mahesh,

 

Until unless you generate a traffic that is initiated from server to PC... you do not need any ACL...

 

Becoz firewall does the stateful packet filtering and it will automatically allow the return traffic with identified value of the sequence number... But in case of icmp or something u need to allow specific on both outgoing and incoming interfaces.....

 

hope this helps.

View solution in original post

1 Reply 1

nkarthikeyan
Level 7
Level 7

Hi Mahesh,

 

Until unless you generate a traffic that is initiated from server to PC... you do not need any ACL...

 

Becoz firewall does the stateful packet filtering and it will automatically allow the return traffic with identified value of the sequence number... But in case of icmp or something u need to allow specific on both outgoing and incoming interfaces.....

 

hope this helps.

Review Cisco Networking for a $25 gift card