03-14-2006 07:01 AM - edited 03-03-2019 12:03 PM
Am I better to place the CBAC inspection on the outside "out" or inside "in" interface?
Is there a rule as with standard and exteneded ACLs?
Solved! Go to Solution.
03-14-2006 03:23 PM
Yes, I would also think that it's better to apply it in the outside interface because that is more likely to be the point of entry for malicious traffic.
Paresh
03-14-2006 03:11 PM
Hi,
The general rule with filtering is to filter as early as possible. However, your circumstances will dictate whether you place it on the inside or the outside interface.
Paresh
03-14-2006 03:16 PM
I'm guessing unless I need specific inspections for the inside "in" ie DMZ and LAN I would be better putting this on the outside "out" to prevent un-necessary traffic coming into the router then getting dropped?
I ask because I inherited two routers on a new network, one seems to filter on LAN other onthe outside.
03-14-2006 03:23 PM
Yes, I would also think that it's better to apply it in the outside interface because that is more likely to be the point of entry for malicious traffic.
Paresh
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide