cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1559
Views
5
Helpful
4
Replies

Reflexive ACLs with cisco ISR4331

omer shtivi
Level 1
Level 1

Hello,

Does cisco ISR 4331 support reflexive ACLs?

Is there another feature that will allow us to do allow only RDP through an interface and block incoming traffic but allow the connection of the RDP?

 

 

Thanks,

Omer Shtivi

1 Accepted Solution

Accepted Solutions

Omer

I had a check of Feature Navigator and couldn't see any mention of reflexive acl support although it is not always entirely accurate in what it tells you.

I suspect if you want stateful inspection you are meant to use ZBFW on those routers.

Jon

View solution in original post

4 Replies 4

Jon Marshall
Hall of Fame
Hall of Fame

Not sure about reflexive acls but from your description you may be able to do it with normal acls.

What exactly do you want to do ie. in terms of interfaces ?

Jon

Hi John,

Thank you for your response.

 

We can't do it with extended ACLs because we want the routers to do statefull inspection (which normal ACLs are unable to do)

 

explanation about reflexive ACL:

http://www.cisco.com/c/en/us/td/docs/ios/12_2/security/configuration/guide/fsecur_c/scfreflx.html

 

Omer

Omer

Sorry I should have been clearer.

I know what reflexive acls are, I just wasn't sure if they were supported on the ISR 4331 that's all.

I'll have a quick check.

Jon

Omer

I had a check of Feature Navigator and couldn't see any mention of reflexive acl support although it is not always entirely accurate in what it tells you.

I suspect if you want stateful inspection you are meant to use ZBFW on those routers.

Jon