Cisco Bug: CSCuo15557 - VTY ACL with permit established keyword, permits all hosts to SSH in
Last Modified
Feb 09, 2017
Products (1)
- Cisco MDS 9000 NX-OS and SAN-OS Software
Known Affected Releases
6.1(3) 6.1(4a)
Description (partial)
Symptom: Customer has an ACL configured for the VTY lines using the access-class command. All incoming SSH requests seem to be getting matched and permitted by the acl entry with "established" keyword and not just the connections with ack bit set. It appears that the established keyword is not working. Conditions: VTY ACL with "permit tcp any any established" configured at the be beginning of the ACL with no specific deny statements prior to it.
Bug details contain sensitive information and therefore require a Cisco.com account to be viewed.
Bug Details Include
- Full Description (including symptoms, conditions and workarounds)
- Status
- Severity
- Known Fixed Releases
- Related Community Discussions
- Number of Related Support Cases