Useless egress in SG zone?

2014-01-24 Thread Nux!
Hi, I'm testing ACS 4.2 + XS 6.2 with Basic Zone and it kind of works great, but the Egress rules seem to be useless. Since all outgoing traffic is accepted by default, what is their purpose? Lucian -- Sent from the Delta quadrant using Borg technology! Nux! www.nux.ro

Re: Useless egress in SG zone?

2014-01-24 Thread Marcus Sorensen
Are you talking about the rules that ensure an instance can't bring up and use IP addresses that are not assigned to it? On Jan 24, 2014 4:10 PM, "Nux!" wrote: > Hi, > > I'm testing ACS 4.2 + XS 6.2 with Basic Zone and it kind of works great, > but the Egress rules seem to be useless. Since all o

Re: Useless egress in SG zone?

2014-01-24 Thread Nux!
On 25.01.2014 01:12, Marcus Sorensen wrote: Are you talking about the rules that ensure an instance can't bring up and use IP addresses that are not assigned to it? I'm not sure. Here's a pic: http://img.nux.ro/jC4b-Selection_015.png The anti-spoofing is working ok, supposedly, but I was expe

Re: Useless egress in SG zone?

2014-01-27 Thread Jayapal Reddy Uradi
Hi Nux, 1. By default we are allowing egress in SG. 2. But when you configure any rule in egress, it allows ONLY configured rule traffic and other traffic will be BLOCKED. If admin wants allow to only specific ports/addresses this can be done by configuring SG egress rules. In my firewalls, t

Re: Useless egress in SG zone?

2014-01-28 Thread Nux!
On 28.01.2014 05:20, Jayapal Reddy Uradi wrote: Hi Nux, 1. By default we are allowing egress in SG. 2. But when you configure any rule in egress, it allows ONLY configured rule traffic and other traffic will be BLOCKED. If admin wants allow to only specific ports/addresses this can be done by