Learn how to a build a cloud-first strategyRegister Now

x
?
Solved

How do I block traffic between interfaces on a Cisco 2600 router.

Posted on 2005-05-05
1
Medium Priority
?
377 Views
Last Modified: 2012-06-27
I have 4 ethernet interfaces on my cisco 2600 router that connect to 4 seperate internal networks.

What is the best way to block traffic originating from interface 1 from going to interface 3, but still allow it to go to interface2&4 and visa versa.

I setup an access-list to deny the IP ranges on interface1&3, but ended up blocking all traffic.

I had:

access-list 3 deny ip 10.1.2.0 0.0.0.255
access-list 4 deny ip 10.1.3.0 0.0.0.255

with access-list 3 applied to inbound on interface 1, and access-list 4 applied to inbound on interface 3. This led to all IP traffic being denied however, which forced me to console in and remove the access-list.

0
Comment
Question by:jcc05
1 Comment
 
LVL 50

Accepted Solution

by:
Don Johnston earned 400 total points
ID: 13936023
You need an "access-list # permit any"

At the end of every access list (but is not shown) is what an implicit deny any.

So your access-list 3 actually was:

access-list 3 deny 10.1.2.0 0.0.0.255
access-list 3 deny any

So just add the "access-list 3 permit any" and you'll be all set.

-Don
0

Featured Post

Free Tool: ZipGrep

ZipGrep is a utility that can list and search zip (.war, .ear, .jar, etc) archives for text patterns, without the need to extract the archive's contents.

One of a set of tools we're offering as a way to say thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

While it is possible to put two routes in place with the secondary having a higher metric, this may not always work. In the event of a failure that does not bring down the physical interface on the router the primary route is not removed. There is a…
It happens many times that access list (ACL) have to be applied to outgoing router interface in order to limit some traffic.This article is about how to test ACL from the router which is not very intuitive for everyone. Below scenario shows simple s…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

810 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question