cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
736
Views
5
Helpful
3
Replies

Deny RDP traffice on PIX

simonator
Level 1
Level 1

Good day CSC,

I am trying to configure an acl to deny rdp traffic on one of our server which has a static nat from one of our public IP. How can I configure it without dropping all other traffic? Will these configuration do it?

 

access-list (acl name) deny tcp any host (Public IP of server) eq 3389

access-list (acl name) permit ip any any

access-group (acl name) in interface outside

 

 

Attached also is the sanitized configuration of the PIX firewall so anyone can see what is configured in it.

 

Thanks in advance for all your help and replies :)

3 Replies 3

pmahesh01
Level 1
Level 1

access list seems ok but dont see any reason to add the IP any any rule on the outside interface.

 

Coz of the implicit deny?

you will always want to block any request coming from outside other the ones you allowing.

Review Cisco Networking for a $25 gift card