We help IT Professionals succeed at work.

accesslist help

Medium Priority
209 Views
Last Modified: 2012-05-06

permit tcp any eq 110 any

i have applied the above to the outbound of an interface, what does the permit statment does?

with that rule my internal server is able to connect to extermal email server

im wonderin which "any" means the external mail server

Comment
Watch Question

Top Expert 2009
Commented:
Is it outbound towards the email server (outbound on the VLAN interface of the mail server) or is it outbound towards the external server?

If outbound towards the internal email server, it allows the return traffic from the external mail server.  The first any is the source, in this case the external mail server.  The second any is the destination, in this case your mail server.

If outbound towards the external mail server, it has no effect (well, it allows source ports of 110 to any destination) this would be required for connections to your mail server on 110 (inbound connections).

Not the solution you were looking for? Getting a personalized solution is easy.

Ask the Experts

Author

Commented:
its outbound towards internal mail server

so tthat means if x.x.x.x is externail mail server
permit tcp x.x.x.x eq 110 host 192.168.20.20

that means 192.168.20.20 recieves mail from x.x.x.x
correct?
Top Expert 2009

Commented:
The internal mail server 192.168.20.20 makes a connection to x.x.x.x on port 110 so the access-list rule allows the return traffic where x.x.x.x has a source port of 110 and the destination is 192.168.20.20.  This is needed because it is outbound toward the internal mail server.
Access more of Experts Exchange with a free account
Thanks for using Experts Exchange.

Create a free account to continue.

Limited access with a free account allows you to:

  • View three pieces of content (articles, solutions, posts, and videos)
  • Ask the experts questions (counted toward content limit)
  • Customize your dashboard and profile

*This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

OR

Please enter a first name

Please enter a last name

8+ characters (letters, numbers, and a symbol)

By clicking, you agree to the Terms of Use and Privacy Policy.