19.07.2013 Views

Cisco 860 Series, Cisco 880 Series, and Cisco 890 Series ...

Cisco 860 Series, Cisco 880 Series, and Cisco 890 Series ...

Cisco 860 Series, Cisco 880 Series, and Cisco 890 Series ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Appendix B Concepts<br />

Access Lists<br />

OL-1<strong>890</strong>6-03<br />

<strong>Cisco</strong> <strong>860</strong> <strong>Series</strong>, <strong>Cisco</strong> <strong>880</strong> <strong>Series</strong>, <strong>and</strong> <strong>Cisco</strong> <strong>890</strong> <strong>Series</strong> Integrated Services Routers Software Configuration Guide<br />

Access Lists<br />

With basic st<strong>and</strong>ard <strong>and</strong> static extended access lists, you can approximate session filtering by using the<br />

established keyword with the permit comm<strong>and</strong>. The established keyword filters TCP packets based on<br />

whether the ACK or RST bits are set. (Set ACK or RST bits indicate that the packet is not the first in the<br />

session <strong>and</strong> the packet therefore belongs to an established session.) This filter criterion would be part of<br />

an access list applied permanently to an interface.<br />

B-11

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!