Link to home
Start Free TrialLog in
Avatar of Jelonet
Jelonet

asked on

Suspicious ACL in router config

I'm not very acl or router savvy so I bring this to you for an explanation.  I am looking at the ACL's in our router and see a large number of hits on one line of the acl that I don't understand.  Our public IP space is X.140.0.0/16 using  private inside addresses. This looks extremely suspicious to me.  should I be seeing this many hits on a deny statement? Should I be concerned?  If so, how do I fix this situation?

 
 20 deny ip X.140.0.0 0.0.63.255 X.140.0.0 0.0.63.255 (12311 matches)
 
Avatar of rsivanandan
rsivanandan
Flag of India image

It depends on which direction the traffic is flowing through. Can you paste your configuration here (sanitized of course)

Cheers,
Rajesh
Avatar of Jelonet
Jelonet

ASKER

I cant paste the config here but this acl is for internet to inside "ip access-group OUTSIDE_INSIDE in" is on the s0/0 facing ISP
SOLUTION
Avatar of rsivanandan
rsivanandan
Flag of India image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
ASKER CERTIFIED SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of Jelonet

ASKER

Sorry I couldn't get back here until now.  I'll have to do a little more research on the ip address scheme.  Thank you for your responses.