Always match all with port-filter
For ports you want to enable, use match not port xxx.

Note: rotary command which is supposed to open a port, also needs to be
added as match not port.
Note1: udp which has not session, needs to be matched here as RIP

On Sat, May 7, 2011 at 9:42 AM, Andrey <[email protected]> wrote:

> Vybhav,
>
> Your solution not work, it simply drop all traffic.
> Try to use match not port and it will be blocked with your configuration,
> you need match-all type in that case
> On May 7, 2011 3:29 PM, "Vybhav Ramachandran" <[email protected]> wrote:
>
> _______________________________________________
> For more information regarding industry leading CCIE Lab training, please
> visit www.ipexpert.com
>
> Are you a CCNP or CCIE and looking for a job? Check out
> www.PlatinumPlacement.com
>



-- 
Bruno Fagioli (by Jaunty Jackalope)
Cisco Security Professional
_______________________________________________
For more information regarding industry leading CCIE Lab training, please visit 
www.ipexpert.com

Are you a CCNP or CCIE and looking for a job? Check out 
www.PlatinumPlacement.com

Reply via email to