My friend Mike Storm has come up with a good "base" ACL for use on Internet facing routers and firewall devices. While he has it listed on his blog, I am referencing it here for my own future reference.
Assuming my PubNet range is a block of 32 66.238.29.0 - 31. See below
! no fragments
access-list 100 deny tcp any 66.238.29.0 0.0.0.31 log fragments
access-list 100 deny udp any 66.238.29.0 0.0.0.31 log fragments
access-list 100 deny icmp any 66.238.29.0 0.0.0.31 log fragments
! no snmp inbound from the Internet
access-list 100 deny udp any any eq snmp
access-list 100 deny udp any any eq snmptrap
Recent comments
1 day 7 hours ago
1 day 15 hours ago
3 days 1 hour ago
5 days 14 hours ago
5 days 16 hours ago
6 days 52 min ago
6 days 53 min ago
6 days 52 min ago
6 days 9 hours ago
1 week 5 days ago