cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
504
Views
0
Helpful
1
Replies

Difference between CBAC and Reflexive access-list

Can anyone tell me the difference between the CBAC and Reflexive Access-list. Their purpose look identical to me, but the commands are different.

Any help would be highly appreciated.

Thank you.

Mohan

1 Reply 1

gfullage
Cisco Employee
Cisco Employee

CBAC turns your router into a stateful device, so it doesn't just update the access-list to allow return traffic back in (like reflexive ACL's do), it keeps track of the state of the connection, monitoring ACK/SEQ numbers in TCP packets, etc. Go with CBAC over reflexive ACL's any day, much more secure.