My cisco router receives its dynamic ip address and nameservers from the cablemodem. I have a few questions regarding this...
This line is included in the ACL for my CableModem interface, without it I don't get an ip address:
access-list 101 permit udp any eq bootps any eq bootpc
Does this look correct, or can it be more defined ? (I notice this lets in other packets not ment for me)
I'm now setting up DDNS w/no-ip.com, which requires that I turn on IP DOMAIN LOOKUP. Which also requires DNS (domain) entries for the ACL, here is what I added:
access-list 101 permit udp any eq domain any
access-list 101 permit tcp any eq domain any
My first question with this is why do I need these entries in the ACL when I have 'ip inspect' for both tcp and udp in the same interface ? I assume the router does not use ip inspect when it decides to send out some packets ?
Can I somehow limit the 2 entries above to only the current nameservers ?
Since the first ACL line allows BOOTP/DHCP requests out, you can't really hard-core the source/destination addresses. Depending on which DHCP state your router is in, the addresses may either be 0.0.0.0, 255.255.255.255 or the acual IPs. Therefore, if you tighten it any more, you risk breaking it.
As for the second lot, you can indeed hard-core the DNS server IPs, as the previous poster noted. One other thing you can do without too much impact is to just allow DNS through UDP. TCP/53 is only used for DNS zone transfers and large (>512 byte) messages so in most cases, it can be pretty safely denied.
Question We run asr9001 with XR 6.1.3, and we have a very long delay to
login w/ SSH 1 or 2 to the device compare to IOS device. After
investigation, the there is 1s delay between the client KEXDH_INIT and
the server (XR) KEXDH_REPLY. After debug ssh serv...
Introduction The purpose of this document is to demonstrate the Open
Shortest Path First (OSPF) behavior when the V-bit (Virtual-link bit) is
present in a non-backbone area. The V-bit is signaled in Type-1 LSA only
if the router is the endpoint of one or ...
Hi, I am seeing quite a few issues with patch install and wanted to
share my experience and workaround to this. Login to admin via CLI, then
access root with the “shell” command Issue “df –h” and you’ll probably
see the following directory full or nearly ...