Re: router policy question

2010-04-16 Thread Glenn English
On Apr 16, 2010, at 8:35 PM, Daniel D Jones wrote: >> But is there any reason at all to allow anything, aside from some ICMP, to >> go beyond the ACL on its Internet facing interface -- to get to the router >> itself, that is? > > You mean packets coming in from the Internet with a destination I

Re: router policy question

2010-04-16 Thread Daniel D Jones
On Friday 16 April 2010 21:00:56 Glenn English wrote: > On my nets, I need to be able to telnet/ssh into the border router, from > the inside, to futz with it. > > But is there any reason at all to allow anything, aside from some ICMP, to > go beyond the ACL on its Internet facing interface -- t

router policy question

2010-04-16 Thread Glenn English
On my nets, I need to be able to telnet/ssh into the border router, from the inside, to futz with it. But is there any reason at all to allow anything, aside from some ICMP, to go beyond the ACL on its Internet facing interface -- to get to the router itself, that is? -- Glenn English g...@