Purpose - deny access to the firewall (save for specific exceptions) I always thought that if you specified some telnet hosts on the inside and SSH ones the outside that "it was implicit" that no other access could be made via these protocols. But to stealth the box should one actually ALSO have an ACL that says effectively, "permit specific telnet hosts tcp to access inside interface eq 23" and simlar for SSH hosts on the outside hosts - thus implicity denying all others this access ??