> The 5300xl does not support the established
> option, or one that is like that.
That explains way I couldn't find it...
It also means that the ACL implementation in the 5300XL is rather useless (for me at least). I want to block all incoming traffic except for a few selected services. Without an established option or some session management like in a real firewall this cannot be done.
Can anyone explain why the default last entry in an ACL is an implicit deny? If you don't have an established-option the implicit deny is almost always wrong. An implicit permit would make much more sense.
> The reason I use gt 1024, is because a
> client that connects to a server, allways
> connects from a source port above 1024.
Unless it is RSH or NFS which by default picks a privileged port...
> Hope this helped,
> Kell
It sure did! Now I will return the 5300XL and shop for some another product.
Does anyone have a recommendation for something that can route 1Gbit/s and do have a usable ACL implementation? OSPF and VLAN are required. A Procurve 9304 worked all right but is a bit expensive. I real firewall would be nice of course but price vs performance is a tough one.
/jens