Compare cert salaries and plan your next career move
Netstudent wrote: your fa4 port is getting an IP from the DHCP right? It looks like the DHCP is leasing out private adresses. Then you are NAT overloading that interface. So are you overloading to a private IP?
Delirious wrote: I applied the "incoming" acl to the f4 port on my 871(advanced IP)and now can't: 1.ftp directory listing fails (it connects but fails to retrieve directory listing, filezilla) 2.get to an external web site 3.torrent works on port 65500 can: 1. telnet into router from another network 2. rdp into my machine on port 63389 3. get to my website hosted on internal machine so its partially working i just cant figure out why ftp and internet access isnt working? can someone please help me, i know its probably something simple but i'm not seeing it. <snip>
Delirious wrote: I applied the "incoming" acl to the f4 port on my 871(advanced IP)and now can't: 1.ftp directory listing fails (it connects but fails to retrieve directory listing, filezilla) 2.get to an external web site 3.torrent works on port 65500 can: 1. telnet into router from another network 2. rdp into my machine on port 63389 3. get to my website hosted on internal machine so its partially working i just cant figure out why ftp and internet access isnt working?
again this is for ftp client sessions initiated from your inside network. - passive ftp uses data port gt 1023 permit tcp any eq ftp host 74.75.113.20 gt 1023 permit tcp any gt 1023 host 74.75.113.20 gt 1023 - active ftp uses ftp-data port 20 permit tcp any eq ftp host 74.75.113.20 gt 1023 permit tcp any eq ftp-data host 74.75.113.20 gt 1023 this will work but from this you can see the vulnerabilities opened when using stateless ACL's.
permit tcp any host 74.75.113.20 eq www the above entry will work for traffic initiated from outside to inside but to allow return traffic initiated from inside you will need to allow this. permit tcp any eq www host 74.75.113.20 gt 1023 as for the ftp from inside to outside its a bit more complicated and depends on if your client is doing active or passive mode ftp.
Compare salaries for top cybersecurity certifications. Free download for TechExams community.