Advertisement

06.23.2008 at 02:54AM PDT, ID: 23507005
[x]
Attachment Details

Frustrating Cisco Access list problom

Asked by webleyaxsor in Network Routers

Tags: Cisco, IOS, 12.4, Access list help

Hi,

I have a router up and running, I am just trying to add a access list rule to allow TFTP (for backing up IOS etc),
It sounds simple but I cannot get it to work, spent ages fiddling around now, it works if i disable the access list from the dilaer interface so i know it where the problem is, enclosed is the config for the affected areas,

interface Dialer1
 bandwidth 800
 ip address negotiated
 ip nat outside
 ip inspect swd out
 ip access-group 111 in
 ip virtual-reassembly
 encapsulation ppp
 dialer pool 1
 dialer-group 1
 no cdp enable
 ppp authentication chap pap callin
 ppp chap hostname xxxxxxxxxxxxxxxxxxx
 ppp chap password xxxxxxxxxxxxxxxxxxx
 ppp pap sent-username xxxxxxxxxxxxxxxxxx password xxxxxxxxxxx
 service-policy output qos-policy
 hold-queue 224 in



access-list 111 permit esp any any
access-list 111 permit udp any eq domain any
access-list 111 permit tcp any eq domain any
access-list 111 permit gre any any
access-list 111 permit udp any any eq isakmp
access-list 111 permit icmp any any echo
access-list 111 permit icmp any any echo-reply
access-list 111 permit tcp any any eq 1723
access-list 111 permit udp any any eq 1723
access-list 111 permit tcp host 1.1.1.1 host 2.2.2.2 eq 22
access-list 111 permit tcp host 1.1.1.1 host 2.2.2.2 eq telnet
access-list 111 permit udp host 1.1.1.1 host 2.2.2.2 eq tftp
access-list 111 permit udp any any eq tftp
access-list 111 permit udp any any eq non500-isakmp
access-list 111 deny   ip any any log


1.1.1.1 is the remote device and 2.2.2.2 is the dilaer interface ip address, please help it's driving me nuts, to make matter worse the telnet and ssh rules work !!

Thanks guysStart Free Trial
[+][-]06.23.2008 at 04:38AM PDT, ID: 21845121

View this solution now by starting your 7-day free trial. Setting up your free trial is quick, easy, and secure. We will return you to this solution, unlocked, when you're done.

 

About this solution

Zone: Network Routers
Tags: Cisco, IOS, 12.4, Access list help
Sign Up Now!
Solution Provided By: donjohnston
Participating Experts: 1
Solution Grade: A
 
 
[+][-]07.10.2008 at 11:42AM PDT, ID: 21976269

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]07.10.2008 at 11:46AM PDT, ID: 21976296

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
 
Loading Advertisement...
20080716-EE-VQP-32 / EE_QW_2_20070628