Reflexive ACL question

Can the inbound and outbound ACLs in a reflexive ACL live on different interfaces like CBAC.  So the mirroring on the ingress of the "inside" interface.  And the mirrored on the "outside."

example:


ip access-list extended inside

 permit tcp any any reflect mirror

 permit udp any any reflect mirror

ip access-list extended outside

 deny   ip any any

 evaluate mirror 

 


interface FastEthernet0/0

 description inside

 ip address 192.168.1.2 255.255.255.0

 ip access-group inside in

 speed 100

 full-duplex

!

interface FastEthernet0/1

 description outside

 ip add 192.168.2.2 255.255.255.0

 ip access-group outside in

Comments

Sign In or Register to comment.