Cisco IOS BVI ACL: Only allow established UDP
- by George Bailey
Related: Cisco IOS ACL: Don't permit incoming connections just because they are from port 80
I know we can use the established keyword for TCP.. but what can we do for UDP (short of replacing a Bridge or BVI with a NAT)?
Answer
I found out what "UDP has no connection" means.
DNS uses UDP for example..
named (DNS server) is lisenting on…