Compare cert salaries and plan your next career move
kryolla wrote: It is the same thing if you apply it to the inbound on the inside interface or outbound on the outside interface. Inbound inside interface permits temp holes in the interface acl where the traffic is switched to i.e inside is e0/0 and outside is s0/0 and e1/0 (DMZ) so there is an acl on s0/0 inbound with deny ip any any and whatever traffic originated on e0/0 and destined out s0/0 will open a temp hole in the deny ip any any acl for return traffic. If you apply it to the outside interface s0/0 outbound it will work the same and open holes in the acl applied inbound to the outside interface. So if you only have 2 interfaces on your router you would want to put on the outside interface outbound inspect and inbound deny ip any any. If you put the inspect in the inside interface inbound it will work but the router will monitor all traffic coming into that interface including traffic destined for the router. If you have 3 interfaces including DMZ you would want to put the inspect rule in the inside interface to permit return traffic from the DMZ or the internet. You DMZ inbound interface should have a deny ip any any. HTHcisco ios firewall config guide
Compare salaries for top cybersecurity certifications. Free download for TechExams community.