Solved

Access-list not working properly??

Posted on 2004-08-04
7
273 Views
Last Modified: 2010-04-17
Hi,

I have created the following access-list;

access-list 110 permit tcp any host x.x.x.10 eq www
access-list 110 permit tcp any host x.x.x.10 eq 443
access-list 110 permit tcp any host x.x.x.10 eq 22
access-list 110 permit tcp any host x.x.x.12 eq smtp
access-list 110 permit tcp any host x.x.x.12 eq pop3
access-list 110 permit tcp any host x.x.x.12 eq 22
access-list 110 permit icmp any any unreachable
access-list 110 permit icmp any any echo
access-list 110 permit icmp any any echo-reply
access-list 110 permit icmp any any time-exceeded

access-list 115 permit ip any any

Then I applied them to my serial interface which is connected to my ISP

int s0
ip access-group 110 in
ip access-group 115 out

Problem:

The problem is in-coming works fine, and I can ssh in from external to x.x.x.10 and 12. And I can receive email. But for out-going traffic I cannot ssh out, I cannot surf the net and ping, and I cannot send emails. I'm using cisco 1700 with IOS Version 12.1(2). Both machines (10 and 12) are using public IPs.

Can anyone help me? Thanks

0
Comment
Question by:smw42
7 Comments
 
LVL 36

Accepted Solution

by:
grblades earned 150 total points
ID: 11724794
Add the following to the beginning of the access list
access-list 110 permit tcp any any established

Currently you are not permitting the reply packets to come back into the serial interface.
0
 
LVL 79

Expert Comment

by:lrmoore
ID: 11725183
You also need to permit dns replys back in.
Add this line also:

access-list 110 permit udp any eq domain any

0
 
LVL 1

Expert Comment

by:kuro2ck
ID: 11727093
Post the rest of your config then we can see all your nat statements too.
0
Control application downtime with dependency maps

Visualize the interdependencies between application components better with Applications Manager's automated application discovery and dependency mapping feature. Resolve performance issues faster by quickly isolating problematic components.

 
LVL 28

Expert Comment

by:mikebernhardt
ID: 11731374
Why bother using access-list 115 at all if you're permitting everything? It has no effect on your question, which has already been well-answered. But no access-list and access-group is the same as what you have, but without the fuss.
0
 

Author Comment

by:smw42
ID: 11732766
access-list 115 was coz i could not get out going traffic,. so i just added that to test.

did not setup net. so my access-list shouldn't have much configuration

thanks.
0
 

Author Comment

by:smw42
ID: 11732770
did not set up nat i mean
0
 

Author Comment

by:smw42
ID: 11732802
how do i give points to the other answers too?? sorry i'm new to ee
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Cisco ACS TACACS server - adding a secondary 2 62
Error on login Cisco RV016 1 32
2 routers, one cable modem 10 85
Quality settings for cisco routers 8 51
We've been using the Cisco/Linksys RV042 for years as: - an internet Gateway - a site-to-site VPN device - a leased line site-to-site subnet-to-subnet interface (And, here I'm assuming that any RV0xx behaves the same way as an RV042.  So that's …
I recently attended Cisco Live! in Las Vegas, a conference that boasted over 28,000 techies in attendance, and a week of hands-on learning hosted by a solid partner with which Concerto goes to market.  Every year, Cisco displays cutting-edge technol…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

932 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now