You are on page 1of 4

Listas de acesso – Interfaces de gerência do MSAN e gerência de modems G.

SHDSL:

interface vlanif<VLAN ID>


description Interface de Gerencia do DSLAM
ip address <IP ADDRESS MGMT> <MASK DECIMAL>
firewall packet-filter 3191 inbound

acl number 3191


description Controle de acesso ao equipamento
rule 1 deny tcp fragment
rule 2 deny udp fragment
rule 3 deny icmp fragment
rule 4 deny ip fragment
rule 5 permit ip source 10.18.70.24 0
rule 6 permit ip source 10.18.70.25 0
rule 10 permit icmp icmp-type echo
rule 11 permit icmp icmp-type echo-reply
rule 12 permit icmp icmp-type ttl-exceeded
rule 13 permit icmp icmp-type host-unreachable
rule 14 permit icmp icmp-type port-unreachable
rule 15 permit icmp icmp-type protocol-unreachable
rule 16 permit icmp icmp-type net-tos-redirect
rule 17 permit icmp icmp-type host-tos-redirect
rule 20 permit udp source 200.153.1.130 0
rule 22 permit udp source 200.204.246.7 0
rule 31 permit udp source 200.204.1.108 0 destination-port eq snmp
rule 32 permit udp source 201.95.253.21 0 destination-port eq snmp
rule 33 permit udp source 201.95.253.22 0 destination-port eq snmp
rule 34 permit udp source 201.95.253.23 0 destination-port eq snmp
rule 35 permit udp source 201.95.253.24 0 destination-port eq snmp
rule 36 permit udp source 201.95.253.25 0 destination-port eq snmp
rule 37 permit udp source 201.95.253.26 0 destination-port eq snmp
rule 38 permit udp source 201.95.253.27 0 destination-port eq snmp
rule 39 permit udp source 201.95.253.28 0 destination-port eq snmp
rule 40 permit udp source 201.95.253.29 0 destination-port eq snmp
rule 41 permit udp source 201.95.253.30 0 destination-port eq snmp
rule 42 permit udp source 201.95.253.31 0 destination-port eq snmp
rule 43 permit udp source 201.95.253.32 0 destination-port eq snmp
rule 44 permit udp source 201.95.253.33 0 destination-port eq snmp
rule 45 permit udp source 201.95.253.44 0 destination-port eq snmp
rule 46 permit udp source 201.95.253.45 0 destination-port eq snmp
rule 60 permit udp source 200.204.1.121 0 destination-port eq 1812
rule 61 permit udp source 200.204.1.121 0 destination-port eq 1813
rule 62 permit udp source 200.204.1.122 0 destination-port eq 1812
rule 63 permit udp source 200.204.1.122 0 destination-port eq 1813
rule 74 permit tcp source 200.153.1.130 0 destination-port eq telnet
rule 76 permit tcp source 200.204.1.108 0 destination-port eq telnet
rule 77 permit tcp source 200.204.246.7 0 destination-port eq telnet
rule 78 permit tcp source 200.204.1.4 0 destination-port eq telnet
rule 79 permit tcp source 201.95.253.21 0 destination-port eq telnet
rule 80 permit tcp source 201.95.253.22 0 destination-port eq telnet
rule 81 permit tcp source 201.95.253.23 0 destination-port eq telnet
rule 82 permit tcp source 201.95.253.24 0 destination-port eq telnet
rule 83 permit tcp source 201.95.253.25 0 destination-port eq telnet
rule 84 permit tcp source 201.95.253.26 0 destination-port eq telnet
rule 85 permit tcp source 201.95.253.27 0 destination-port eq telnet
rule 86 permit tcp source 201.95.253.28 0 destination-port eq telnet
rule 87 permit tcp source 201.95.253.29 0 destination-port eq telnet
rule 88 permit tcp source 201.95.253.30 0 destination-port eq telnet
rule 89 permit tcp source 201.95.253.31 0 destination-port eq telnet
rule 90 permit tcp source 201.95.253.32 0 destination-port eq telnet
rule 91 permit tcp source 201.95.253.33 0 destination-port eq telnet
rule 92 permit tcp source 10.18.72.50 0 destination-port eq telnet
rule 93 permit tcp source 10.18.72.52 0 destination-port eq telnet
rule 94 permit tcp source 10.18.37.10 0 destination-port eq telnet
rule 95 permit udp destination-port range 33434 33690
rule 96 permit udp source 200.204.1.103 0 destination-port eq ntp
rule 98 permit udp source 200.204.0.10 0 destination-port eq dns
rule 99 permit udp source 200.204.0.138 0 destination-port eq dns
rule 110 deny ip

interface vlanif<VLANID>
description Gerencia dos MODEMS - Lado Assinante
ip address <GW_MODEMS> <MASK_GW_MODEMS>
firewall packet-filter 3090 inbound

acl number 3090


description Controle de acesso ao equipamento
rule 1 deny tcp fragment
rule 2 deny udp fragment
rule 3 deny icmp fragment
rule 4 deny ip fragment
rule 10 permit icmp icmp-type echo
rule 11 permit icmp icmp-type echo-reply
rule 12 permit icmp icmp-type ttl-exceeded
rule 13 permit icmp icmp-type host-unreachable
rule 14 permit icmp icmp-type port-unreachable
rule 15 permit icmp icmp-type protocol-unreachable
rule 16 permit icmp icmp-type net-tos-redirect
rule 17 permit icmp icmp-type host-tos-redirect
rule 20 permit udp source 0.0.0.0 0 destination 200.153.1.130 0
rule 22 permit udp source 0.0.0.0 0 destination 200.204.246.7 0
rule 31 permit udp source 0.0.0.0 0 destination 200.204.1.108 0 destination-port eq
snmp
rule 32 permit udp source 0.0.0.0 0 destination 201.95.253.21 0 destination-port eq
snmp
rule 33 permit udp source 0.0.0.0 0 destination 201.95.253.22 0 destination-port eq
snmp
rule 34 permit udp source 0.0.0.0 0 destination 201.95.253.23 0 destination-port eq
snmp
rule 35 permit udp source 0.0.0.0 0 destination 201.95.253.24 0 destination-port eq
snmp
rule 36 permit udp source 0.0.0.0 0 destination 201.95.253.25 0 destination-port eq
snmp
rule 37 permit udp source 0.0.0.0 0 destination 201.95.253.26 0 destination-port eq
snmp
rule 38 permit udp source 0.0.0.0 0 destination 201.95.253.27 0 destination-port eq
snmp
rule 39 permit udp source 0.0.0.0 0 destination 201.95.253.28 0 destination-port eq
snmp
rule 40 permit udp source 0.0.0.0 0 destination 201.95.253.29 0 destination-port eq
snmp
rule 41 permit udp source 0.0.0.0 0 destination 201.95.253.30 0 destination-port eq
snmp
rule 42 permit udp source 0.0.0.0 0 destination 201.95.253.31 0 destination-port eq
snmp
rule 43 permit udp source 0.0.0.0 0 destination 201.95.253.32 0 destination-port eq
snmp
rule 44 permit udp source 0.0.0.0 0 destination 201.95.253.33 0 destination-port eq
snmp
rule 45 permit udp source 0.0.0.0 0 destination 201.95.253.44 0 destination-port eq
snmp
rule 46 permit udp source 0.0.0.0 0 destination 201.95.253.45 0 destination-port eq
snmp
rule 60 permit udp source 0.0.0.0 0 destination 200.204.1.122 0 destination-port eq
1812
rule 61 permit udp source 0.0.0.0 0 destination 200.204.1.122 0 destination-port eq
1813
rule 62 permit udp source 0.0.0.0 0 destination 200.204.1.121 0 destination-port eq
1812
rule 63 permit udp source 0.0.0.0 0 destination 200.204.1.121 0 destination-port eq
1813
rule 74 permit tcp source 0.0.0.0 0 destination 200.153.1.130 0 destination-port eq
telnet
rule 76 permit tcp source 0.0.0.0 0 destination 200.204.1.108 0 destination-port eq
telnet
rule 77 permit tcp source 0.0.0.0 0 destination 200.204.246.7 0 destination-port eq
telnet
rule 78 permit tcp source 0.0.0.0 0 destination 200.204.1.4 0 destination-port eq
telnet
rule 79 permit tcp source 0.0.0.0 0 destination 201.95.253.21 0 destination-port eq
telnet
rule 80 permit tcp source 0.0.0.0 0 destination 201.95.253.22 0 destination-port eq
telnet
rule 81 permit tcp source 0.0.0.0 0 destination 201.95.253.23 0 destination-port eq
telnet
rule 82 permit tcp source 0.0.0.0 0 destination 201.95.253.24 0 destination-port eq
telnet
rule 83 permit tcp source 0.0.0.0 0 destination 201.95.253.25 0 destination-port eq
telnet
rule 84 permit tcp source 0.0.0.0 0 destination 201.95.253.26 0 destination-port eq
telnet
rule 85 permit tcp source 0.0.0.0 0 destination 201.95.253.27 0 destination-port eq
telnet
rule 86 permit tcp source 0.0.0.0 0 destination 201.95.253.28 0 destination-port eq
telnet
rule 87 permit tcp source 0.0.0.0 0 destination 201.95.253.29 0 destination-port eq
telnet
rule 88 permit tcp source 0.0.0.0 0 destination 201.95.253.30 0 destination-port eq
telnet
rule 89 permit tcp source 0.0.0.0 0 destination 201.95.253.31 0 destination-port eq
telnet
rule 90 permit tcp source 0.0.0.0 0 destination 201.95.253.32 0 destination-port eq
telnet
rule 91 permit tcp source 0.0.0.0 0 destination 201.95.253.33 0 destination-port eq
telnet
rule 95 permit udp destination-port range 33434 33690
rule 96 permit udp source 0.0.0.0 0 destination 200.204.1.103 0 destination-port eq ntp
rule 98 permit udp source 0.0.0.0 0 destination 200.204.0.10 0 destination-port eq dns
rule 99 permit udp source 0.0.0.0 0 destination 200.204.0.138 0 destination-port eq dns
rule 110 deny ip

You might also like