|
|
| Unix Administration Firewall Intrusion Detection Network Security Hacking MORE HOME |
interface xx (outer/inner) access-group in 100 access-group out 100 access-list 100 deny ip host 0.0.0.0 any access-list 100 deny ip 127.0.0.0 0.255.255.255 any access-list 100 deny ip 10.0.0.0 0.255.255.255 any access-list 100 deny ip 172.16.0.0 0.15.255.255 any access-list 100 deny ip 192.168.0.0 0.0.255.255 any access-list 100 deny ip 192.0.2.0 0.0.0.255 any access-list 100 deny ip 169.254.0.0 0.0.255.255 any access-list 100 deny ip 240.0.0.0 15.255.255.255 any access-list 100 permit ip any any
ip verify unicast reverse-path
ip verify unicast source reachable-via any
interface xy no ip source-route no ip directed-broadcast no ip proxy-arp no ip redirects no ip unreachables no ip mask-reply no cdp enable
interface xy rate-limit input access-group 100 8000 8000 8000 \ conform-action transmit exceed-action drop rate-limit output access-group 100 8000 8000 8000 \ conform-action transmit exceed-action drop access-list 100 deny tcp any host x.x.x.x established access-list 100 permit tcp any host x.x.x.x access-list 101 permit icmp any any echo access-list 101 permit icmp any any echo-reply
| CopyLeft (l) 2003 by Raffael Marty |