Solved

block a single IP or a range of IPs on PIX

Posted on 2007-03-26
5
434 Views
Last Modified: 2010-04-12
I want to block a specific host from reaching my dmz subnet.

In the example the host is 182.135.34.250 and the IP of the dmz subnet is 198.128.181.0/24

These lines don't work.

access-list outside deny ip host 182.135.34.250 host 198.128.181.226
access-list outside deny ip host 182.135.34.250 198.128.181.0 255.255.255.0

What am I doing wrong?
0
Comment
Question by:nummagumma2
5 Comments
 
LVL 28

Accepted Solution

by:
batry_boy earned 168 total points
ID: 18796493
As long as the translated public IP address of the DMZ subnet is 198.128.181.xxx then it should work as long as it's applied to the outside interface.  What do your statics and access-group statements look like?
0
 
LVL 79

Assisted Solution

by:lrmoore
lrmoore earned 166 total points
ID: 18800102
They should work fine. Can you post result of "show access-list". Look for increase # in (Hitcount= xxx)
Do you have any permit statements above it? i.e.
 access-list outside permit tcp any host 198.128.181.226 eq www
 access-list outside deny ip host 182.135.34.250 host 198.128.181.226

The permit will allow the packet and will never hit the deny.
0
 
LVL 29

Assisted Solution

by:Alan Huseyin Kayahan
Alan Huseyin Kayahan earned 166 total points
ID: 18800994
make sure you tagged this acl group to interface by typing
access-group outside in interface dmz
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Cisco ASA 5505 ios upgrade 6 45
Cisco IOS from ipbase to ipservices 10 78
How do to revert to start-up config on a Cisco Switch Stack 11 33
ACL Logging Optimization 7 30
If you have an ASA5510 then this sort of thing would be better handled with a CSC Module, however on an ASA5505 thats not an option, and if you want to throw in a quick solution to stop your staff going to facebook during work time, then this is the…
Use of TCL script on Cisco devices:  - create file and merge it with running configuration to apply configuration changes
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…

867 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

15 Experts available now in Live!

Get 1:1 Help Now