I've inherited a cisco 2600 as an external router. While I'm familiar with firewalling extensivly using IPtables and linux. I'm wonder about a couple of thing's I've read in some documents.
Firt my setup is as follows. (if you need more let me know)
T1 line into 2600 from ISP.
Line from 2600 into a switch.
1) If I'm writing an acl for IP based traffic to block certain ports and protocols comming in from the internet where do I apply them?
The T1 line interface serial 0/0 or Ethernet 0/0?
2) If I'm blocking the external traffice comming in do I apply it to the interface "in" or "out"? How exactly does that work? The reason I ask is I had a Cisco tech set a rule up do to ICMP flooding comming in and he put the rule on Ethernet 0/0 out.
3) If "out" is correct what would you use "in" for? For traffic going from my network to the internet?
4) In what situation would you put rules on the Line interface, in my case Serial 0/0? (I think)
Thanks for your help,
Cheers,
Scully
Firt my setup is as follows. (if you need more let me know)
T1 line into 2600 from ISP.
Line from 2600 into a switch.
1) If I'm writing an acl for IP based traffic to block certain ports and protocols comming in from the internet where do I apply them?
The T1 line interface serial 0/0 or Ethernet 0/0?
2) If I'm blocking the external traffice comming in do I apply it to the interface "in" or "out"? How exactly does that work? The reason I ask is I had a Cisco tech set a rule up do to ICMP flooding comming in and he put the rule on Ethernet 0/0 out.
3) If "out" is correct what would you use "in" for? For traffic going from my network to the internet?
4) In what situation would you put rules on the Line interface, in my case Serial 0/0? (I think)
Thanks for your help,
Cheers,
Scully