Guest

Preview Tool

Cisco Bug: CSCuo15557 - VTY ACL with permit established keyword, permits all hosts to SSH in

Last Modified

Feb 09, 2017

Products (1)

  • Cisco MDS 9000 NX-OS and SAN-OS Software

Known Affected Releases

6.1(3) 6.1(4a)

Description (partial)

Symptom:
Customer has an ACL configured for the VTY lines using the access-class command.
All incoming SSH requests seem to be getting matched and permitted by the acl entry with "established" keyword and not just the connections with ack bit set. It appears that the established keyword is not working.

Conditions:
VTY ACL with "permit tcp any any established" configured at the be beginning of the ACL with no specific deny statements prior to it.
Bug details contain sensitive information and therefore require a Cisco.com account to be viewed.

Bug Details Include

  • Full Description (including symptoms, conditions and workarounds)
  • Status
  • Severity
  • Known Fixed Releases
  • Related Community Discussions
  • Number of Related Support Cases
Bug information is viewable for customers and partners who have a service contract. Registered users can view up to 200 bugs per month without a service contract.