Table 13-1: Cisco-Supplied Default Filter Rules - Cisco VPN 3000 User Manual

Table of Contents

Advertisement

13
Policy Management
For all the default rules except VRRP In and Out , these parameters are identical:
Action
Source Address
Destination Address
For maximum security and control, we recommend that you change the Source Address and Destination
Address

Table 13-1: Cisco-supplied default filter rules

Filter Rule Name Direction
Any In
Any Out
CRL over LDAP In
CRL over LDAP Out Outbound
GRE In
GRE Out
ICMP In
ICMP Out
IKE In
IKE Out
Incoming HTTP In
Incoming HTTP
Out
Incoming HTTPS
In
Incoming HTTPS
Out
IPSec-ESP In
L2TP In
L2TP Out
LDAP In
LDAP Out
OSPF In
OSPF Out
Outgoing HTTP In
Outgoing HTTP
Out
13-10
= Forward
= Use IP Address/Wildcard-Mask = 0.0.0.0/255.255.255.255 = any address
= Use IP Address/Wildcard-Mask = 0.0.0.0/255.255.255.255 = any address
to fit your network addressing and security scheme.
Protocol
Inbound
Any
Outbound
Any
Inbound
TCP
TCP
Inbound
GRE
Outbound
GRE
Inbound
ICMP
Outbound
ICMP
Inbound
UDP
Outbound
UDP
Inbound
TCP
Outbound
TCP
Inbound
TCP
Outbound
TCP
Inbound
ESP
Inbound
UDP
Outbound
UDP
Inbound
TCP
Outbound
TCP
Inbound
OSPF
Outbound
OSPF
Inbound
TCP
Outbound
TCP
TCP
TCP/UDP
Connection
Source Port
Don't Care
Range 0-65535
Don't Care
Range 0-65535
Don't Care
LDAP (389)
Don't Care
Range 0-65535
Range 0-65535
IKE (500)
Don't Care
Range 0-65535
Don't Care
HTTP (80)
Don't Care
Range 0-65535
Don't Care
HTTPS (443)
Range 0-65535
L2TP (1701)
Don't Care
Range 0-65535
Don't Care
LDAP (389)
Don't Care
HTTP (80)
Don't Care
Range 0-65535
TCP/UDP
ICMP
Destination Port
Packet
Type
Range 0-65535
0-255
Range 0-65535
0-255
Range 0-65535
LDAP (389)
0-18
0-18
IKE (500)
Range 0-65535
HTTP (80)
Range 0-65535
HTTPS (443)
Range 0-65535
L2TP (1701)
Range 0-65535
LDAP (389)
Range 0-65535
Range 0-65535
HTTP (80)
VPN 3000 Concentrator Series User Guide

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents