ACL Applied in Inbound direction and another ACL exist for in outbound direction - will return traffic allow

interface gix/y
ip address A.B.C.D 255.255.255.192
ip access-group ACL-Inbound in
ip access-group ACL-Outbound out
exit
In ACL-Inbound I have allowed SMTP traffic 6 source address to 4 destination server. One sample output among 24 acl is given below.
permit tcp host E.F.G.H host I.J.K.L eq 25
I haven't applied any specific rule for SMTP traffic on outbound direction. My understanding is destinations will be able to reply to the request. Does that need to be specified in the ACL

Disclaimer
The Author of this posting offers the information contained within this posting without consideration and with the reader's understanding that there's no implied or expressed suitability or fitness for any purpose. Information provided is for informational purposes only and should not be construed as rendering professional advice of any kind. Usage of this posting's information is solely at reader's own risk.
Liability Disclaimer
In no event shall Author be liable for any damages whatsoever (including, without limitation, damages for loss of use, data or profit) arising out of the use or inability to use the posting's information even if Author has been advised of the possibility of such damage.
Posting
As Fahad has already noted, if you're going to use both an in and out ACL, you'll need to account for the traffic allowed in both direction.  Normally, the in and out ACE are just mirror entries, so for your example of:
in
permit tcp host E.F.G.H host I.J.K.L eq 25
out would be:
permit tcp host I.J.K.L eq 25 host E.F.G.H
Fahad also mentioned using a Reflexive ACL.  These will generate a stateful mirror ACE for the reverse traffic.  The reverse ACE will stay active for a short duration after seeing traffic that creates it and the it will time out and remove itself.  Normally you would only use one on a trusted side of the device for generated flows.  When used with a trusted side, the ACE often are made more generic, for example, any inside to outside HTTP flow will allow and ACE for the return traffic.

Similar Messages

  • HT204053 I set up one apple id for icloud on my iphone and another apple id for ipad.  I cannot use icloud to automatically sync the two.

    I set up one apple id for icloud on my iphone and another apple id for ipad.  I cannot use icloud to automatically sync the two.

    How can I delete the incorrect apple id?

  • Have one WiFi signal into the apartment for my Air, and another wifi signal for my 5c phone plan. Both from the same provider. Expensive. Is there a way to 'combine' WiFi signals so I pay only for one, but can get on the Internet with my Air?

    Have one WiFi signal into the apartment for my Air, and another wifi signal for my 5c phone plan. Both from the same provider. Expensive. Is there a way to 'combine' WiFi signals so I pay only for one, but can get on the Internet with my Air?

    Roamingnome, thanks for your response. Although I have been a Bell (Canada) customer for my WiFi signal for years, the 5c and its necessary mobility plan, is very recent. Some years ago, Bell supplied its own ‘router’ for my computer, and claimed that it was possible to get their WiFi signal only with the router they supplied. When I recently received the 5c, I wondered if the plan it requires, which is within the much wider, overall Bell zone, could be used somehow to get my Air online - some sort of tethering? - that allows me to give up the Air WiFi service and router all together, but still get the Air connected. Here in Canada, Bell Mobility and other Bell services are very separate. Any suggestions appreciated.

  • I have one apple ID for my iTunes and another apple ID for everything else. if I download the new OS, can I switch my iTunes apple ID once it's all downloaded?

    my family all shares one apple ID for iTunes so we can share music. but I have my own apple ID for my phone and ipad. on my phone, I can have two separate IDs, but I'm wondering if its the same for my macbook pro. If i download the new OS, it asks for my apple ID. I would like to put in my personal one so that i can get texts and such. but I would want my iTunes to be my family account. is this possible?

    You can use one account with iTunes on your Mac, and different account(s) with the Mac App Store (for buying/downloads apps or OS updates for your Mac), iCloud (System Preferences > iCloud) and Messages (Messages > Preferences, or command-comma)

  • G555. Need drivers for SM Bus and another Unknown device for Windows XP.

    I try to install Windows XP on my G555. I got all other drivers, but cannot find drivers for SM Bus and an Unknown device. And what's this device?
    The second problem is that after I installed all the drivers, the card reader disappeared. It was there after I installed Windows XP, before I install drivers.
    Thanks a lot.
    A Simpleguy
    Solved!
    Go to Solution.

    Hi Simpleguy,
    Welcome to the forum!
    In thinkpads, it's usually intel chipset driver. For AMD based G555, I wouldn't be surprised if this is the driver you need:- http://consumersupport.lenovo.com/us/en/DriversDownloads/drivers_show_2476.html
    As for other unknown device, find it's PCI ID with any other known information and paste here.
    Hope it helps.
    Maliha (I don't work for lenovo)
    ThinkPads:- T400[Win 7], T60[Win 7], IBM 240[Win XP]
    IdeaPad: U350
    Apple:- Macbook Air [Snow Leopard]
    Did someone help you today? Compliment them with a Kudos!
    Was your question answered today? Mark it as an Accepted Solution! 
      Lenovo Deutsche Community     Lenovo Comunidad en Español 
    Visit my YouTube Channel

  • I want a seperate address book for contacts, and another contact list for the phone. Anyone?

    Just got an iphone (yay!) and the icloud sync-ed my contact list form my first generation ipad. Hoever, I do not want this info in the contact list the phone accesses (2 different lists). Is there a way to keep them seperate? With the latest operating system (installed this morning) I can't see the contacts I manually entered into the phone unless I download from the cloud (which has EVERY contact in it-not just the manually entered conrtacts). Surely there must be ways to create groups, or different phone/contact lists to access?

    till now i don't think thunderbird has multiple address books. but u can try rd party app but still i don't recommend this. If i 'll get any info about this i will definately tell you. sorry but if it won't helps.

  • Using airport express for itunes and another wireless network for internet

    Is there any way i can use my airport express just for playin music through airtunes, and log onto the internet using a different wireless network?

    Hello bleno567. Welcome to the Apple Discussions!
    Is there any way i can use my airport express just for playin music through airtunes, and log onto the internet using a different wireless network?
    Yes, you just need to configure the AirPort Express Base Station (AX), that will be used to stream iTunes, as a wireless client.

  • While on a call and another comes it isn't showing on the screen or allowing me to switch over or even answer the other call. What do I do?

    I have had my phone since Jan and have never had this problem before. It won't show who is calling or let me swap calls and hangs up the call that is coming in if I hang up or if caller 1 hangs up. Can someone please help me?????

    Thank you so very much! My husband is in Afghanistan and calls at different times. If I am on a call and can't answer him it could be days before I hear from him again. I never thought to just restart my phone! Duh...this is my first smartphone so I am learning. All day people were calling while I was on the phone but I couldn't answer. Thank GOD none of the calls were my husband because it would break my heart if I missed his call. Thank you again and GOD bless you! Ashley Combahee

  • I can't open tabs on my MacBook Pro. I have uninstalled and re-installed Firefox several times, but it will still not allow me to open other tabs after it has gone to my homepage.

    I cannot open any tabs on Firefox. It opens to my homepage, but there is no line for a URL address. Therefore, there is no way to type in a new URL address. I have uninstalled and reinstalled Firefox twice and it has not helped. I am a former PC user and just switched to Mac.

    Try restore as new using computer iTunes.

  • Dropped 3gs into lake for 2 hours.  Found and put in rice for sev. days.  Will come on when connected to power, but not pc.  Goes out after min. or so.  Will it likely work again without service or am I dreaming?

    As mentioned above, I dropped my Iphone 3gs into lake and it took me about two hours to fish it out.  I put it in a jar of rice for over a week.  It will now come on only if I plug it into the electrical oulet.  It will not come on using the usb connection on the pc.  It also cuts out after a short time - usually about a minute or so.  Will this phone likely work correctly again without major service or should I just forget it?  I have aready bought a replacement to use, but I hate to just toss it if it may work again.  Also, is there anything else I can do short of taking it in to the Apple store?  I suspect the cost of service will not be justified.

    You are welcome.  There are always suggestions of things to try, but in the end you just get frustrated and end up taking it in anyway...save yourself the trouble and visit the Apple store genius bar.

  • I purchased a mac book-pro over 2 years ago and it keeps asking for updates that it will only let me update using the old users apple ID, i cant figur out how to remove it i wint to an apple store and they were stumped

    i cant get rid of the other users ID,  i have tired to remove this id many many times,  it will let me use my ID to do updates but it will nto let me do the updates associated that id the original user.  any  ideas

    Delete all of the applications associated with that Apple ID.
    (119669)

  • ACL-advices for my topology

    Hi,
    I attach my topology, so please have look at it while you read my quest.
    I need to know how to make my cisco-router01 as secure as possible on the "outside"-interface and still allow all traffic through the tunnel. Is there anyone who has some advice how I should configure my ACL:s?
    Regards,
    Johannes

    Thank you very much for your answer!
    My VPN-tunnel goes from a virtual "tunnel-interface" (interface Tunnel1). Is it possible to put one acl on the "outside"-interface and another in the "tunnel"-interface. Or will the tunnel-interface get affected by the ACL that I put on the outside-interface? Sorry if this is stupid questions, I do not have the chance to test stuff on this environment, so I need to be sure that it will work
    I currently have a ACL on the "outside-"interface that allows traffic from 10.201.0.0/16 IN.
    /Johannes

  • Recently purchased song and another I transfered into my ITunes library vannot be set up in a playlist.I get the message"file cannot be located".Originally I could listen to the purchased song but now that will no longer play.What do I need to do to ?

    Recently purchased a song from ITunes and another that I downloaded from a CD will not transfer to a playlist and will not even allow me to listen to the songs.I get the message "file cannot be located"What can I do to get my system to locate the file?Originally I could play the songs from my desktop and I was able to transfer to my IPad.

    Because the location for each song in your library is on your hard drive.  If the hard drive isn't there, how can iTunes play it?
    You'll have to move/copy the music from your hard drive to your computer's hard drive.
    Basically, EASIEST way to do all this, if you don't care about your play counts, etc...
    -Delete EVERYTHING from iTunes, so that your library is now empty.
    -Go to "Advanced" inside of the "Preferences" window, found in the "Edit" drop-down.  You can also access Preferences by pressing Ctrl+, (Press Ctrl and the comma key)
    -Change your iTunes Media Folder Location to something simple, but on your computer. I use C:/iTunes.  Make sure "Keep iTunes Media Folder Organized" and "Copy files to...." are both checked.  You can close Preferences now.
    -Now, drag and drop your music from your hard drive into your iTunes library.  iTunes will automatically add the music to your library, as you would expect, and also creates a copy of each file to place into that iTunes Media Folder you just created.
    Shouldn't have any more problems...

  • I have IMAC and use Aperture and I am looking for a good App to turn a photograph into a painting look

    I have an IMAC and use Aperture and I am looking for a App that will allow me to have one of my photos look like a painting - any suggestions?  It is a gift for my brother

    I like photoshop elements.
    http://www.photoshopelementsuser.com/blog/from-photograph-to-painting/
    You can also do something like this:
    http://www.luminous-landscape.com/tutorials/new_page_9.shtml

  • Exchange 2013 and 2010 co-existance

    We will have 2013 and 2010 exist together for a while...we plan to move away from using Unified Access Gateway for HTTP redirection to our Exchange services and implement Kemp
    load balancers...two at our HQ site and two at our DR stie...
    We plan to have a one arm configuration...from what I gathered...each load balancer will have a network connection and only one network connection and be on the same network as
    our new Exchange 2013 servers.  Can someone take a look at my config and give some input whether or not this will work and some suggestion on Ex13 urls, cert SAN names, etc.
    HQKemp 2400 A    
    HQKemp 2400 B               
    DCKemp 2400 A        DCKemp 2400 B
    172.16.1.104        
    172.16.1.105                     
    172.25.1.104          
    172.25.1.10
    Virtual IP   172.16.1.106          
                             Virtual IP 
    172.25.1.104
    From the video I’ve watched for Kemp install…we’ll create the following internal DNS records for the Exchange services that will be configured on balancers.
    OWA/ECP   
        mail.corp.local.com
                  172.16.1.107
    EWS               ews.corp.local.com          
    172.16.1.108
    OAB               oab.corp.local.com           
    172.16.1.109
    ActiveSync      mobile.corp.local.co         
    172.16.1.110
    OA                 oa.corp.local.com            
    172.16.1.111
    Autodiscover   autodiscover.corp.local.com 172.16.1.112
    Question: 
    We will configure the Exchange services with these ip addresses linked to each service on all four load balancers? 
    Or will DR site load balancers have different IPs configured for same Exchange services?
    Exchange services are split between our two sites…meaning Outlook Anywhere is configured for our CAS servers at our DR site and ActiveSync comes to HQ CAS servers as an example…so
    I want all Exchange services to come through the newly installed load balancers at HQ and if they don’t respond…the Exchange services get redirected to the load balancers at our DR site. 
    Can you give some insight on the config of load balancers as to how we can do that?
    I have a question about the cert we will have. 
    Our Microsoft rep says we should get a new wildcard cert…currently we have a UCC cert with the following SANs attached.
    Will this new cert have to be installed on load balancers? 
    If so…can you suggest some ideas as to what new SANs I need if any of the new cert with Exchange 2010 and 2013 co-existing for a while. 
    Below are the SANs on our current UCC cert.
    Outside resolvable SANs
    Webmail.corp.local.com          
    205.223.19.25           portal.corp.local.com     205.223.27.78
    Portal2.corp.local.com             
    205.223.19.25         
    Autodiscover.corp.local.com     
    205.223.19.25
    Internal SANs  
    Hqcas1.corp.local.com              
    Hqcas2.corp.local.com              
    Dccas1.corp.local.com              
    Dccas2.corp.local.com              
    Owamail.corp.local.com     
    (this CAS Array server name that HQ CAS servers create)
    What do you suggest we use for the external urls on Exchange 2013 for these services?
    Our firewall guy says we’ll use same names, 
    but I’m not sure if we try to use same name if we’ll get an error? 
    Active Directory may say name already in use?
    We plan to have firewall to just redirect requests for external urls to load balancers…sound correct? 
    Meaning load balancer won’t have an external NIC defined…which makes it a one arm config…correct?

    Hi Techy,
    According to your description, I am still not quite sure about your environment. Could you please provide more information about it, such as:
    1. How many Exchange servers in your coexistence environment? One Exchange 2010 with all roles and one Exchange 2013 with all roles? Or several Exchange 2010 and multiple Exchange 2013?
    2. Are there two sites in your environment? What’s the Exchange deployment in different sites?
    3. Please confirm if both Exchange 2010 and Exchange 2013 are Internet-facing.
    Additionally, if you are using different namespaces for different services for internal access and external accessing, we need to include all service namespaces in your certificate with IIS service. Personal suggestion, we can follow ED Crowley’s suggestion
    to use split-brain DNS in your environment and only use the same namespace for Exchange service URLs.
    The following article described the details about how to configure different namespace for Exchange services by using Load Balance in Exchange 2013:
    http://www.msexchange.org/articles-tutorials/exchange-server-2013/high-availability-recovery/introducing-load-balancing-exchange-server-2013-part2.html
    Regards,
    Winnie Liang
    TechNet Community Support

Maybe you are looking for