cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1378
Views
0
Helpful
2
Replies

Difference between CBAC and Reflexive access-list

What exactly is the difference between CBAC and Reflexive accesslist?

For me, both look similar. When to use what? Thanks

2 Replies 2

gfullage
Cisco Employee
Cisco Employee

You asked this back on April 10th, and I answered it as follows:

-----------------------------------------------------------------------

CBAC turns your router into a stateful device, so it doesn't just update the access-list to allow return traffic back in (like reflexive ACL's do), it keeps track of the state of the connection, monitoring ACK/SEQ numbers in TCP packets, etc. Go with CBAC over reflexive ACL's any day, much more secure.

------------------------------------------------------------------------

Hi, Thank you for your reply. Sorry I missed to see your previous reply. Thanks again for posting the answer for me. That was helpful.

Best Regards,

Mohan