router ACL

Unanswered Question
Feb 24th, 2008

I am confused with the access-list requirement for IPS.

IPS device will create dynamically generated ACL to the router in the event that a signature is triggered. It requires an existing access-list defined as Pre-block access list and an existing access-list defined as post-block access list.

Does this mean that I need to set up at least 3 access-list on my router, one for normal use that is applied to the interface, another one to be defined as pre-block access-list on IPS device and a third one to be defined as post-block access-list on the IPS device?

Thanks

I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
owillins Fri, 02/29/2008 - 07:32

Could you specify what device you are using and its configuration?

eppiet Fri, 02/29/2008 - 09:39

The router is a 2600 and ips is 4215. Currently I only have one set of access-list. That's why I don't understand how I can have a pre and a post access-list to be used by the IPS device.

Actions

This Discussion