Solved

Cisco 1605-R

Posted on 2006-10-23
5
289 Views
Last Modified: 2010-04-17
I have a 1605-R Cisco Router. I need to shrink my configuration.. I'm running Version 11.2

Here is what my config looks like

access-list 103 permit ip 10.0.0.1 0.0.0.255 host IP1
access-list 103 permit ip 10.0.0.1 0.0.0.255 host IP2
access-list 103 permit ip 10.0.0.1 0.0.0.255 host IP3
access-list 103 permit ip 10.0.0.1 0.0.0.255 host IP4

access-list 103 permit ip 10.0.0.21 0.0.0.255 host IP1
access-list 103 permit ip 10.0.0.21 0.0.0.255 host IP2
access-list 103 permit ip 10.0.0.21 0.0.0.255 host IP3
access-list 103 permit ip 10.0.0.21 0.0.0.255 host IP4

So i have this huge access list with random IPs which need to access the same 4 IPs. Is there anyway to create a group??

Thanks
0
Comment
Question by:inf2300
  • 2
5 Comments
 
LVL 79

Expert Comment

by:lrmoore
ID: 17791894
>access-list 103 permit ip 10.0.0.1 0.0.0.255 host IP4
>access-list 103 permit ip 10.0.0.21 0.0.0.255 host IP1

Since 10.0.0.1 and 10.0.0.21 are both covered by mask 0.0.0.255, then
All you need is one set of 4 lines:

 access-list 103 permit ip 10.0.0.0 0.0.0.255 host IP1
 access-list 103 permit ip 10.0.0.0 0.0.0.255 host IP2
 access-list 103 permit ip 10.0.0.0 0.0.0.255 host IP3
 access-list 103 permit ip 10.0.0.0 0.0.0.255 host IP4




0
 

Author Comment

by:inf2300
ID: 17795346
Thanks for the reply...

I can't do that because it's punctual IPs that need access and not the entire range. For example i would need to access to 10.0.0.21, 10.0.0.36, 10.0.0.164. I know it would be very simple if i could put them in the same subnet but i can't. I don't control that network.

So is there anyway to create a group that would contain IP1, IP2, IP3 & IP4 so that i would only then have one line per 10.0.0.0 IP. This would shrink my config by 75%

Thanks
0
 
LVL 79

Accepted Solution

by:
lrmoore earned 500 total points
ID: 17795419
>access-list 103 permit ip 10.0.0.1 0.0.0.255 host IP4
Given the mask that you show here "0.0.0.255" you are already including the entire range of 10.0.0.0/24.
There is no value in continuing with it the way it is.

You would have to change it to:
access-list 103 permit ip host 10.0.0.1 host IP1
access-list 103 permit ip host 10.0.0.1 host IP2
access-list 103 permit ip host 10.0.0.1 host IP3
access-list 103 permit ip host 10.0.0.1 host IP4
access-list 103 permit ip host 10.0.0.21 host IP1
access-list 103 permit ip host 10.0.0.21 host IP2
access-list 103 permit ip host 10.0.0.21 host IP3
access-list 103 permit ip host 10.0.0.21 host IP4

Given this, and given that there is not way to create a group for acls in IOS (you can with PIX FW), your best bet may be to choose a shorter list of IPs to allow. Instead of inividual permits which allows all but a handful of hosts, how about the other way around - use a shorter list of deny and one permit:

access-list 103 deny ip host 10.0.0.13 host IP1
access-list 103 deny ip host 10.0.0.13 host IP2
access-list 103 deny ip host 10.0.0.13 host IP3
access-list 103 deny ip host 10.0.0.13 host IP4

access-list 103 deny ip host 10.0.0.22 host IP1
access-list 103 deny ip host 10.0.0.22 host IP2
access-list 103 deny ip host 10.0.0.22 host IP3
access-list 103 deny ip host 10.0.0.22 host IP4

access-list 103 permit ip 10.0.0.0 0.0.0.255 host IP1
access-list 103 permit ip 10.0.0.0 0.0.0.255 host IP2
access-list 103 permit ip 10.0.0.0 0.0.0.255 host IP3
access-list 103 permit ip 10.0.0.0 0.0.0.255 host IP4


0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Join & Write a Comment

Suggested Solutions

In this tutorial I will show you with short command examples how to obtain a packet footprint of all traffic flowing thru your Juniper device running ScreenOS. I do not know the exact firmware requirement, but I think the fprofile command is availab…
I have seen some questions on problems with SSH/telnet access to Cisco routers that may occur despite the fact that from a PC connected to your LAN, Internet connectivity is in place and users can access Internet sites without any issues.  There are…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

743 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

9 Experts available now in Live!

Get 1:1 Help Now