[c-nsp] CBAC and ACL broken for PPPoE on 7513?

Joe Maimon jmaimon at ttec.com
Tue Jul 18 10:35:31 EDT 2006


I have had some issues in the past where ACL's were ignored on 7513 if 
not for "ip inspect" being present on the interface.

Unfortunately TAC was never able to accurately reproduce the problem, 
even though I experienced it consistently.

Now I am suspecting that even on 12.4(8) that certain ACL's are 
"leaking" even with CBAC turned on.

What I would like to know is how realistic is it of me to expect TAC to 
be able to setup a radius server assigning a preconfigured on the router 
ACL (with interface-config VSA, NOT downloaded ACL) to a pppoe user and 
pound it with packets to see what gets by.


More information about the cisco-nsp mailing list