Other types of traffic to consider include the following.
External protocols and IP Addresses
• ICMP from service provider IP Addresses
Explicitly permitted return traffic for internal connections to the Internet
• Specific Internet Control Message Protocol (ICMP) types
• Outbound Domain Name System (DNS) query replies
• TCP established
• User Datagram Protocol (UDP) return traffic
• FTP data connections
• TFTP data connections
• Multimedia connections
Explicitly permitted externally sourced traffic destined to protected internal addresses
• VPN Traffic
• HTTP to web servers
• Secure Socket Layer (SSL) to web servers
• FTP to FTP servers
• Inbound FTP data connections
• Simple Mail Transfer Protocol (SMTP)
• Other applications and servers
• Inbound DNS queries
• Inbound DNS zone transfers
Important: By default, if no conditions match, the software rejects the address.
The switch supports two types of access lists:
• Standard: access list numbers 1–99 and 1300–1999 (expanded range)
• Extended: access list numbers 100–199 and 2000–2699 (expanded range)
59 Asante IntraCore IC36240 User’s Manual