[c-nsp] access list Q

Noel noel.butler at ausics.net
Wed Feb 16 05:25:29 EST 2005


Hi All,

Wanting to rate limit traffic on a port, lets say 25, in and out...

I was of the belief that it's like,  <from> <to> <port>, so 

access-list 119 permit tcp any any eq 25

applied to an interface with in and out would catch, 
but I then applied to same access list

access-list 119 permit tcp any eq 25 any

for the heck of it, however a sh access-list 101 shows vastly different
number of matches on either rule, so was I wrong to assume that  any any
eq 25  applied  in/out would inf act get it all, and I do need both? or
is it just the way the routers caught it?


TIA
N




More information about the cisco-nsp mailing list