Filtering Multiport Applications
Problem
You want to filter an application that uses more than one TCP or UDP port.
Solution
This example shows how to filter both FTP control and data sessions:
Router1#configure terminalEnter configuration commands, one per line. End with CNTL/Z. Router1(config)#access-list152permit tcp any any eq ftpRouter1(config)#access-list152permit tcp any any eq ftp-data establishedRouter1(config)#interfaceRouter1(config-if)#FastEthernet0/0ip access-group152inRouter1(config-if)#exitRouter1(config)#endRouter1#
Discussion
Some protocols use multiple ports. A classic example is FTP, which is shown in the example. It is worthwhile reviewing how the FTP protocol works. For more details, please consult RFC 959.
When a client device wants to connect to a server to either upload or download files, it makes a TCP connection on port 21. This port 21 connection carries all of the interactive user traffic, such as usernames and passwords, as well as commands to move around to different directories. It also uses this control session to tell the server what port number it wants to use for transferring data. This will typically be a high-numbered temporary TCP port.
When the user then wants to transfer a file, he traditionally types a put or get command on the server. We say traditionally because this is not quite how things work when your FTP client software is driven through a web browser, as we discuss in Recipe 19.12.
The server then makes a new TCP connection ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access