Ports/vlan w/o need for acl

On a port or vlan that doesn't need acl filtering is it more effecient to have nothing or a single permit ip any any?  I understand that there's a default implied deny ip any any to block anything not allowed in a proceeding permit statement  but I assume that only applies if an acl is assigned so I would think if you're going to just permit ip any any in an acl with out any denying before it i's better not to waste any processor time running packets through an acl filter since there's nothing to be rejected anyway.

Hi Vini, if I interpret correctly, there is no need for an acess list as it just takes system resources for no need.
-Tom
Please mark answered for helpful posts

Similar Messages

  • Help needed for ACL(7410)

    Hi guys i m working on sun storage 7410 .
    Request you to kindly provide some guideline for using Access Control List on shares.
    Any documentation link will be helpful.

    Hi
    I cannot help you with ACLs directly but you can get the admin guide here: [http://wikis.sun.com/download/attachments/57513819/820-4167-10.pdf|http://wikis.sun.com/download/attachments/57513819/820-4167-10.pdf]
    Last time I took a look at ACLs it was not possible to configure them on the CLI which makes it practically unusable in environments without BUI-access.

  • Need help w/ setting up ports to run a server for America's Army

    Need help w/ setting up ports to run a server for America's Army. I read wat u need to change the ports but i dont understand wat to put. here is wat the site says
    Q: How do I run my own server?
    A: Quick and dirty server info:
    1. Edit RunServer.bat to change the map.
    2. Run RunServer.bat
    Or:
    server.exe LAN MAPNAME.aao (Host a LAN game)
    server.exe global MAPNAME.aao (Host a Public game)
    Also: When you create a server setup and want to allow other users to join your server, you need make sure the following ports are open for outgoing and incoming traffic in your firewall: 1716 (UDP), 1717 (UDP), 20025-20045 (TCP), and 20047 (TCP). Failure to open these ports will prevent the server from accepting connections from other players or prevent other players from being able to see your server online.
    There are several settings that also need to be defined in your server configuration INI file (in the Windows version, these files are located in “My Documents\America’s Army Server Settings\{settings file name}.ini”).
    [Engine.GameEngine]
    ServerActors=Andromeda.AndromedaMBS
    [Andromeda.Andromeda]
    GameServerIp=
    Make sure that you set the actual IP address of the America’s Army Server under GameServerIp= (for example, “GameServerIp=000.000.000.000”). The supplied address must be your actual internet IP address, if this is left blank or you supply the IP address for your internal network (such as 192.168.0.x), your server will not be able to accept connections from the internet.
    If your server.ini file contains the setting shown below, please change the QueryPort setting to 20025. This setting can also be removed, as the default setting is port 20025.
    [Andromeda.AndromedaMBS]
    QueryPort=20025
    Punkbuster user fix correction.
    If [Engine.GameEngine] block has been changed to read as below:
    [Engine.GameEngine]
    ServerActors=IPDrv.AndromedaMBS
    Please add the following block to your INI file:
    [IpDrv.AndromedaMBS]
    QueryPort=20025
    (Last Updated: 2006-04-20)

    Your images are not stored in the catalog. They are stored in folders on your computer. If you imported images that were already on your computer using the "Add" Option they are still in that same folder. If you imported images from your camera then they are in the folders that you specified when you imported. The catalog points to those images wherever they are located, and records all of the adjustments that you make to the image. When you send an image to Photoshop for further editing and save that image in Photoshop, it is normally saved back in the same folder as the original image.
    Images are not "saved" in Lightroom. The basic default workflow in Lightroom is to store all of the adjustments in the catalog, leaving the original image completely unmodified. The catalog becomes the central controlling mechanism. It is a database that contains pointers to where the images are located and a record of all adjustments made to those images using Lightroom. Properly managed, you only have those original master files and secondary files for the ones that you have sent to Photoshop for further adjustment. When you want to provide a copy for someone else, you use the export dialogue for that purpose. I often export JPEG images to share with others or to post on the web. After I have usedthe JPEG for its intended purpose I delete it.

  • How many port numbers do I need assigned for an XIR3 deployment

    How many port numbers are required per XIR3 environment on Linux Red Hat 4/JBOSS/? I only plan to use the following apps (CMC, Infoview, Designer, Report Migration Tool, Import Wizard).
    Am I right in thinking it's four ports ?
    1. 1 for the application
    2. 1 for SIA?
    3. 2 for CMS (Name server port, request port)
    If this is incorrect could someone clarify how many, and what for?
    Many thanks in advance

    Hi there,
    When I look at the Servers list and look at the CMS server I see three potential port numbers:
    1. Request Port
    2. Hostname or IP Address
    3. Name Server Port
    I know we need the third one so can I ask why you say you only need two servers for the CMS, as the list above seem to be suggesting three?
    Thanks for your help in advance

  • Ports needed for CiscoWorks managment

    I am Instaling AP and I don't know which ports should be opened on switch for communication between Access Point and CiscoWork. For now we open all ports to CiscoWorks station, but we want to cut it as much as its possible. Also we've got problems with configuring CiscoWorks to work with AP (AiroNet1130) now it's working but we arn't sure which options are nessesery - so maybe someone could tell me what is exacly needed for this
    Thanks for all replays
    Regards
    Adam

    Here's the official list for CiscoWorks WLSE:
    http://www.cisco.com/en/US/customer/products/sw/cscowork/ps3915/products_user_guide_chapter09186a008052db6f.html
    I thought I saw a post a while ago about some undocumented ports used by WLSE too, but can't find it at the moment.

  • Firewall ports needed for rpc error in powershell

    In my enviroment we use several different DMZ's to host our servers in. This creates a situation where some of the computers in the domains are in different subnets.  I am trying to run a script in one domain in which all the computers are
    in the same subnet except for 2. In this case there is a firewall between the two subnets i am describing. When i try and run my script i recieve the error below. I have verified the following ports are open on the firewall.
    TCP 5985, 5986, 445, 389    TCP\UDP 135
    I have monitored our firewall and the ports being blocked when i run my script are TCP 4754 on one server and 5002 on the other. I believe these are DCOMM ports. What other ports or range of ports, or any other ports, do I need to open to resolve
    the RPC error? I do not want to just open a bunch of unneeded ports between my DMZ's. I could just open these 2 ports and resolve the issue for now, but i am trying to make this a powershell friendly enviroment, if you take my meaning. I should mention all
    local firewalls are turned off on the servers and the script runs fine on all other servers in the subnet.
    Thank You in advance for your help
    Get-WmiObject : The RPC server is unavailable. (Exception from HRESULT: 0x800706BA)
    At C:\Users\jthomas99\Desktop\Get-IPDetails.ps1:14 char:16
    +    $Networks = Get-WmiObject Win32_NetworkAdapterConfiguration -ComputerName $Co ...
    +                ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
        + CategoryInfo          : InvalidOperation: (:) [Get-WmiObject], COMException
        + FullyQualifiedErrorId : GetWMICOMException,Microsoft.PowerShell.Commands.GetWmiObjectCommand
    Thanks for your help

    Here is the DCOM firewall configuration document.  It should be given to your firewall admins and they need to pay special attention to setting up the DCOM port forwarding rules.
    http://support.microsoft.com/kb/154596/en-us
    There are also instructions on how to configure DCOM ports to work with WAN/Internet access issues.
    If you are looking to obtain remote management over a WAN or the Internet you can and should set up WMF as it can be run over a fully encrypted HTTPS port and it does not require odd dynamic port allocation
    as does RPC.
    You can also set up PowerShell Web Service which does not require dynamic ports and can be routed over any port.  It uses the browser to open a PowerShell session on a remote server that can have delegated access to other servers.  DCOM cannot
    do this without making many dangerous changes t your network.
    http://technet.microsoft.com/en-us/library/hh831611.aspx
    ¯\_(ツ)_/¯

  • Why are ports 36000-36999 needed for iChat AV

    I have a homegrown firewall on my network that allows me to do whatever I wish.
    When testing this with a ichat AV 4 user, I had to open the following ports to make it work:
    ${fwcmd} add pass udp from any to any 36000-36999
    ${fwcmd} add pass udp from any 36000-36999 to any
    Once that was done, the video/audio worked fine. I had already punched the other recommended holes:
    ${fwcmd} add pass tcp from any 5190 to any 1024-65535
    ${fwcmd} add pass tcp from any 5298 to any 1024-65535
    ${fwcmd} add pass tcp from any 1024-65535 to any 5190
    ${fwcmd} add pass tcp from any 1024-65535 to any 5298
    ${fwcmd} add pass udp from any 5060-5061 to any 1024-65535
    ${fwcmd} add pass udp from any 5190 to any 1024-65535
    ${fwcmd} add pass udp from any 5297-5298 to any 1024-65535
    ${fwcmd} add pass udp from any 5353 to any 1024-65535
    ${fwcmd} add pass udp from any 5678 to any 1024-65535
    ${fwcmd} add pass udp from any 16384-16403 to any 1024-65535
    Why were the 36000 ports needed?
    Also, when testing with an iChat 3 user, I couldn't initiate the call, but they could and it worked...
    One more thing I should add is that I tested the ichat4 to the appleu3test02 aim user and it worked without punching the 36000 holes.
    Any clues would be very helpful.
    Thanks,
    Micky

    Ok,
    I will tell you which ports iChat 4 uses.
    You can then decide how to enter them into your set up.
    5190 on TCP for AIM Login. An alternative we suggest is 443
    This can be SSL on either port for iChat 4
    5190 on UDP for File Sending, Pic in Text chats (Direct chats) and Group chats.
    5222 and or 5223 on TCP for Jabber login depending on your Server
    5220 for Jabber on TCP (rest of their port use)
    5297, 5298, 5353 on UDP for Bonjour
    5298 on TCP for Bonjour
    5678 on UDP for sending and receiving Visible part of A/V invite
    Ports 16393-16402 on UDP for the SIP connection phase with the SNATMAP server AND the A/V chat it self. Use one port at a time for all of this (Different from iChat 3) Starts at port 16402 and move down one port at a time for those 10 ports then tries random port.
    5900 TCP for Screen Sharing (Unsecure connections) VNC.
    See this Doc for some info
    http://docs.info.apple.com/article.html?artnum=93208
    This for some of the iChat 4 Changes
    http://docs.info.apple.com/article.html?artnum=306688
    This for the VNC bit and confirmation on Port Use and the use of Jabber on some server 5553 in Note 10
    http://docs.info.apple.com/article.html?artnum=106439
    What happens sometimes is that if the other end is doing Port Forwarding, DMZ or Port Triggering with NAT happening in two or more devices then the ports get changed.
    You see this is some Error 8 logs. This in fact itself goes back to info that appeared in the Error log drop down in iChat 2 (And 3 before 10.4.7) that gave you some of the info about how the call was progressing when it failed.
    Doing NAT behind tow or more routing devices can be the problem. It is even worse when people have two DHCP server further complicating the issue.
    I am not sure why you have not pointed them port for port.
    (I know the Apple Doc does says in it's table that this is an option.)
    Most domestic devices via a web browser set up, work fine pointing 5190 at 5190 for example. iChat data is then expected on an iChat port and pointed to an iChat port on your computer.
    Realistically a firewall should work the same way.
    10:23 PM Wednesday; November 14, 2007

  • GE cards supported for port- vlan based EoMPLS on 7600/sup720

    Hi,
    Can anyone explain/point where I can find de proper documentation where I can find the support for port- vlan based EoMPLS support cards on a 7600 with a sup720 engine on the CCO site ?
    WHich GE port cards are supporting EoMPLS and which GE cards will support it not.

    try
    www.cisco.com/go/fn
    -Waris

  • Port needed for File to File scenario

    Hi,
    I am new to XI, just got trained and I want to practice file to file scenario. I am able to access ID and IR.
    I would like to know whether any port have to be enabled for this scenario????
    I got list of ports from the basis people to enable the ports. could you tell me for which scenarios these ports have to be enabled:
    Http Port            50000
    ABAP Port         8000
    Msg server port 3901
    SDM Port            50018
    File Sharing Port  445
    P4 port               50004
    Enqueue server port    3201
    Dispatcher port        3200
    Sql server Port         1433
    Anymaterial to regarding port details would also be helpful.
    Thanks in advance.
    Regards,
    Kiruthiga

    Hi Kiruthiga ,
    I am new to XI, just got trained and I want to practice file to file scenario. I am able to access ID and IR.
    I would like to know whether any port have to be enabled for this scenario????
    --> Not required ..but you ask for FTP site if want to do file to file scenario using FTP . Default FTP port is 21 though ..
    using  got list of ports from the basis people to enable the ports.
    ---> tell them stop sending information which is not required..This is not the way of "Delivering. High Performance. "
    could you tell me for which scenarios these ports have to be enabled:
    Http Port 50000
    ABAP Port 8000
    Msg server port 3901
    SDM Port 50018
    File Sharing Port 445
    P4 port 50004
    Enqueue server port 3201
    Dispatcher port 3200
    Sql server Port 1433
    Any material to regarding port details would also be helpful.
    --> Friend not required...at this point. Though having knowledge is not a harm .
    Regards,

  • Help needed for THE decision

    Hi everyone ☺
    I’m finally planning to start recording what I play, and after some hours of wandering on the web I found some interesting possibilities. Now what I need is to decide which one is more suitable for my needs, and here comes the moment for apple discussions
    Basically, I will record my own music one track/instrument at a time (I’m still not able to play more than one…and I dont’ want to spend 2.000$ to buy a 24-ins device just to record drum tracks), I’d like to have a software with built-in effects for guitar/bass/voice, integrated soundtrack possibilities (to play with video recordings), mixing options for both stereo and surround mixing, and I don’t want any card to be placed into my mac. Well, and obviously the sound quality must be pro-like…as anyone probably wants.
    So, here’s what I came up with:
    a) getting logic pro studio 8 and apogee duet
    b) getting pro tools m-powered and mbox 2
    c) getting one of the two softwares and a Monster iStudioLink Instrument cable and plug instruments directly into the mac
    Now, the questions are:
    if I can plug an instrument directly into my mac and control all parameters via one of the two softwares, what do tools like duet and mbox2 serve for?
    In the case this tools are useful [ ☺ ], why ☺ … and which is the couple software/hardware that can best suit my needs?
    I assume that every software has a proprietary file extension in which audio tracks are saved, so that it should be impossible to record an audio track with one software and edit it with another that has different functions/plugins (ex. from logic to pro tools, from pro tools to cakewalk sonar which I have on a pc etc.). Am I right, or is there any “standard”, non compressed high quality file type in which track can be saved and exported to be edited with different softwares?
    I know that from this post it may easily seem that I’m a hopeless digital idiot, but I swear the situation is not really that bad so no need for the kind of explanations with drawings like the ones you find in the “for dummies” guides lol so every experts’ advice will be greatly appreciated
    Neptune

    Thank you Bee Jay and Pancenter for the lighting-fast and useful answers
    now I am aware that an interface IS NEEDED lol (that means they are not produced without a reasons, are they?). I know Pro Tools is the industry standard but I don't like anyone/anything to tie me to their choices/interests (so that's why I was asking about Pro Tools, knowing that there's some sort of "hardware threat"). What I look for is just quality and if I understood what you both mean, as far as this aspect is concerned, Logic and Pro Tools are substantially comparable...isn't it? On the interfaces side, I already checked the Saffire ones (they seem quite good, and cross-platform use is definitely a plus), I will check the others mentioned and will let you know In fact, I didn't consider the "platform problem" but, as I wrote, I also own a PC with an Audigy 2 soundcard (midi/analog/optical/digital inputs/outputs and firewire port...not Madonna's private studio, but not as sad as Mac's little hole) and Sonar 6 Producer Edition, so that has been a really good point to ponder. And now, in the middle of this software/hardware battle...any personal suggestions based on tests/personal experience?

  • Software needed for the USB device, "USB Interface Controller TEST2.0"

    My mother recently acquired a digital camera. She acquired it from a second-hand store, which did not include an interface cable or software. The manual (and the USB port on the camera) indicates that a male-male USB cable is necessary for photos to be copied to the hard drive.
    I was not successful in locating such a cable at any local electronics store (I assume such a cable is now out-of-date). I purchased one from a seller on eBay. The brand is "e circuit electronics".
    Upon powering up the camera with the cable connected to it and the computer, the following message appeared:
    "Software needed for the USB device "USB Interface Controller TEST2.0" is not available. Would you like to look for the software on the Internet?"
    I clicked "Yes". After an approximate two-minute wait, another message appeared stating:
    "Software Update is not able to connect to the Internet. Please check your configuration and try again."
    I deleted, "Software Update Preferences" in the Preferences folder inside the System Folder, without solving the problem. How do I solve the issue of allowing Software Update to connect to the Internet?

    Thank you for your continued assistance, BDAqua. Unfortunately, the driver you linked to does not seem to be compatible with the camera. It is a driver for the V20 model, whereas my model would correspond to be a V2755, as referenced from a list of other Vivicam models when during a search at the Open Drivers web site.
    From the system requirement about the card reader you gave me, it will not work, as this system is running 9.1. I am hesistant to upgrade this computer to 9.2, as I have experienced system unstability with that version, with even the 9.2.2 update applied.
    In the mean time, I have e-mailed Vivitar regarding this issue, but have as of yet received a reply.
    I am not certain as to other specifics to give you, in order to solve the Software Update problem. Please elaborate.
    Yes eww, the computer in question is able to fully connect to the Internet for all that I need. I am fully aware of the difference between a computer connecting to the Internet, and a computer connecting to a digital camera. I have 15 years of Macintosh experience.

  • What RAM is needed for Laserjet Printer CP1525nw Windows 7 64-bit

    What RAM is needed for Laserjet Printer CP1525nw Windows 7 64-bit

    Hi,
    just found your post...
    To install your HP1010 on Win7do the following:
    Start
    Devices & Printers
    Add a printer
    Adda local printer
    Use an existing port: DOT4_001 (Generic IEEE...)
    Next
    Pick HP from manufacturer
    Select HP LaserJet 3055 PCL5
    Next
    Name the printer something to your liking
    Finish (or so, just follow the prompts)
    Here you are!
    Works every time for me, never had a problem from any application.
    I don't know how this forum works and if i am notified if you reply or anyone else posts on this thread, so i try to check it again soon to check if you left a message.  Be with me...
    Matt

  • What cable do I need for a full migration from a 2011 MacBook Pro to a new current one-wireless migration way too slow.?

    What cable do I need for a full migration from a 2011 MacBook Pro to a new current one-wireless migration way too slow.?

    All you need is an Ethernet cable.
    Just plug it into both machines. Don't bother with a crossover cable, just a plain old Ethernet cable will do. The Ethernet ports on the Macs are smart and will adjust appropriately.

  • What is the type of cable do i need for a macbook white to connect to a hdmi cable?

    what is the type of cable do i need for a macbook white to connect to a hdmi cable? This is quite a problem since macbook white is not in production anymore.

    First we need to know which one of the 9 different models of MacBook you have. To see which model you have go to the Apple in the upper left corner and select About This Mac, then click on More Info (and then System Report if you’re running 10.7 Lion or 10.8 Mountain Lion). When System Profiler comes up check the Model Identifier and post it back here.
    The Late 2008 model 5,1 Aluminum Unibody and the Late 2009 model 6,1 and Mid 2010 model 7,1 White Unibody have a Mini DisplayPort. The Early 2006 model 1,1 through Early 2008 model 4,1s plus the Early and Mid 2009 model 5,2s have Mini-DVI ports. Each would take a different adapter to connect with the TV.

  • What kind of Firewire do I need for the new Mac?

    Hey Apple Community,
    I have a new late 2013 Macbook Pro. I noticed that it has a new firewire port! However, I need to digitize video footage from Mini DV tapes. The camera I'll be using to digitize my footage is a Canon Vixia HV30. Does anyone know what kind of firewire cable I'd need? Will I need an adapter of some sort?
    Thanks for the help!

    What kind of cable would I need exactly? I'd like to look it up and buy what I need today so that I could start my work soon. Here's some reference pictures:
    And do you recommend any particular cable? I'd like to purchase a reliable product.
    Thanks again for the help!

Maybe you are looking for

  • How do I download previous music purchases without having to buy them again

    How do I down load previous music purchases from iTunes.

  • Two times goods receipt is done

    Dear All I am facing one problem ,two times gr is done the same material is done and the material have equipment ( serial number ) is attached. and the serial no profile is having serial no profile and that doesnt allow. and this all happen due to sy

  • What's ObjectId in Crystal Report 2008 for SAP B1 8.8

    Hi all! I am using Crystal Report 2008 for SAP B1 8.8, i don't know ObjectID use for what. In some report temlate of Crystal Report 2008 for SAP B1 8.8, i saw they aways use this. Please explain for me.!! Thanks!

  • How do I find if an R/3 field is in a BW Cube?

    I have a PP BW question I was wondering if anyone knew the answer too.  We are trying to find out if the field VGW02 is available in one of the PP cubes.  This is the MACHINE TIME field from the Routing: Operation Details (CA03 tcode).  Do you know h

  • Diskless x86 solaris 10 (DHCP, PXE booting)

    Has anyone gotten an x86 box to be a diskless client with Solaris 10? I have a server setup(both jumpstart and diskless server) and booting sparc just fine, but I'd like to get an x86 machine working too (you know, for fun :) I have my LX50 jumpstart