[c-nsp] Cbac problem

Paul Stewart pstewart at nexicomgroup.net
Mon Aug 15 16:51:00 EDT 2005


Perfect... Thanks...:)

I thought that CBAC would dynamically open the ports needed?  I can
understand OSPF after feeling kinda dumb, but what about http for
example?  I have an inspect statement setup and it's applied to both
inbound interfaces but without an access list it won't pass traffic?

Thanks,

Paul
 

-----Original Message-----
From: Kevin Graham [mailto:mahargk at gmail.com] 
Sent: Monday, August 15, 2005 4:06 PM
To: Paul Stewart
Cc: cisco-nsp at puck.nether.net
Subject: Re: [c-nsp] Cbac problem

On 8/15/05, Paul Stewart <pstewart at nexicomgroup.net> wrote:

> When I apply an access list as noted, OSPF and everything drops and no

> traffic can pass.  How do I get around this?

CBAC isn't going to inspect OSPF -- make sure you slip a permit for it
before the deny



More information about the cisco-nsp mailing list