! Generated by Network Security Policy Compiler, version 2.453

! [ BEGIN router:stateless ]
! [ Model = IOS ]
! [ Routing ]
! route network:n3 -> interface:stateful.n2
ip route 10.3.3.0 255.255.255.0 10.2.2.2
! [ ACL ]
! interface:stateless.n1
ip access-list extended eth0_in
! permit src=network:n1; dst=host:server; srv=service:ftp-command;
 permit tcp 10.1.1.0 0.0.0.255 host 10.3.3.3 eq 21
! permit src=network:n1; dst=host:server; srv=service:ftp-passive-data; stateless
 permit tcp 10.1.1.0 0.0.0.255 host 10.3.3.3 gt 1023
! permit src=network:n1; dst=host:server; srv=reverse:TCP_ANY; stateless
 permit tcp 10.1.1.0 0.0.0.255 host 10.3.3.3 established
! deny src=network:0/0; dst=network:0/0; srv=auto_srv:ip;
 deny ip any any

! interface:stateless.n2
ip access-list extended eth1_in
! deny src=network:0/0; dst=interface:stateless.n1; srv=auto_srv:ip;
 deny ip any host 10.1.1.1
! permit src=host:server; dst=network:n1; srv=service:ftp-active-data; stateless
 permit tcp host 10.3.3.3 eq 20 10.1.1.0 0.0.0.255 gt 1023
! permit src=host:server; dst=network:n1; srv=reverse:TCP_ANY; stateless
 permit tcp host 10.3.3.3 10.1.1.0 0.0.0.255 established
! deny src=network:0/0; dst=network:0/0; srv=auto_srv:ip;
 deny ip any any

interface eth0
 ip access-group eth0_in in
interface eth1
 ip access-group eth1_in in

! [ END router:stateless ]

