Solved

HowTo access-list blocking a specific port

Posted on 2006-11-01
2
374 Views
Last Modified: 2008-01-09
I have to block all outbound SMTP trafic on one of my interfaces (firewall connection) of a cisco 3650 switch
it should block anything and allow only my mail server trafic.
I set this access list:
Extended IP access list 102
    10 permit tcp host mail_server_IP any eq smtp
    20 deny tcp any any eq smtp

when I try to add that access-list to the required interface I don't have "out" option:
conf t
int g0/1 (the interface I want to block)
ip access-group 102 in (in is the only option & I need out)

what was I doing wrong?
why didn't I get the "out" option?

applying this access-list with "in" option blocked all outbound trafic on this port
0
Comment
Question by:chuku
2 Comments
 
LVL 17

Author Comment

by:chuku
ID: 17866071
found the problem, here is the correct settings:
Extended IP access list 105
    10 permit tcp any host mail_server_ip
    20 permit tcp host mail_server_ip any eq smtp
    30 permit tcp any host mail_server_ip eq smtp
    40 deny tcp any any eq smtp log
    50 permit ip any any
0
 

Accepted Solution

by:
CetusMOD earned 0 total points
ID: 17869906
Closed, 50 points refunded.
CetusMOD
Community Support Moderator
0

Featured Post

Do You Know the 4 Main Threat Actor Types?

Do you know the main threat actor types? Most attackers fall into one of four categories, each with their own favored tactics, techniques, and procedures.

Join & Write a Comment

In a WLAN, anything you broadcast over the air can be intercepted.  By default a wireless network is wide open to all until security is configured. Even when security is configured information can still be intercepted! It is very important that you …
Getting hacked is no longer a matter or "if you get hacked" — the 2016 cyber threat landscape is now titled "when you get hacked." When it happens — will you be proactive, or reactive?
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

758 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

21 Experts available now in Live!

Get 1:1 Help Now