Just tried this with my home lab which has a couple of routers and subnets
on it. I'm not sure if the ftp-data port is necessary. The list seemed to
do its job though.
Extended IP access list 169
permit tcp any any eq ftp established
permit tcp any any eq ftp-data established
deny tcp any any eq ftp
deny tcp any any eq ftp-data
permit ip any any
___________________________________
UPDATED Posting Guidelines: http://www.groupstudy.com/list/guide.html
FAQ, list archives, and subscription info: http://www.groupstudy.com
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]