Without FW it hard. The TCP is only two way traffic (sure icmp also but icmp os only for test) you try acl tcp with established keywords And deny any udp and tcp traffic to pass from outside to inside MHM 0 Helpful Reply MHM Cisco World VIP In response to MHM Cisco World ...