Solved

Use Access lists on mpls network, but now can't access internet

Posted on 2008-06-11
4
205 Views
Last Modified: 2013-11-16
Ok Here it goes....

I found a network on our mpls link that isn't ours in our routing tables.  So I am trying to put access lists on the switches at all our locations.  However, when I apply the access lists all the internal networks can talk, but nothing can go out to the internet.  I thought that I could put a rule to allow any traffic out but the switch will only allow you to apply an access group in.  Besides that I don't know if cisco keeps track of sessions.  ie.  if a packet is allowed out, is it allow to receive the ack if theres no rule to specifically allow that ip?

Ok so heres what I have setup.

access-list 1 permit 10.10.0.0 0.0.255.255
access-list 1 permit 192.168.0.0 0.0.255.255
access-list 1 permit 172.16.0.0 0.0.255.255

I have tried applying the group on all ports of the switches and just the vlans.  

It can traverse the mpls but won't allow you to go out to the internet.  

I tried making a rule to allow any traffic and apply it to an interface out but there is no out command.  

On the 3750s' I'm running 12.2(40)SE and on the 2960s' I'm running 12.2(25)see3.  

Is there some kind of command you need to remember sessions or something?
0
Comment
Question by:Culbert
  • 2
  • 2
4 Comments
 
LVL 16

Expert Comment

by:btassure
ID: 21760387
OK, first you would need to put an allow any statement in as there is an implicit deny at the bottom of every access list.

Second to block the other networks you would need to put the deny at the TOP of the ACL. It would be more efficient to put it like this:

access-list 1 deny ip [unknown network]
access-list 1 permit ip any any

That will let your networks talk to each other and to the internet. The deny statement will be read and processed for the traffic you don't want and will drop it before it gets to the permit stage.

The "in" part of the command means into the interface, not the network. If you were to put that ACL into your edge interfaces you should be fine.
0
 

Author Comment

by:Culbert
ID: 21760443
I can see that this would work but if I start putting deny statements in then if another new network happens to pop up and I don't know about it the default would be to allow all traffic.  Isn't there a way to do this with a default deny rather then default permit?
0
 
LVL 16

Accepted Solution

by:
btassure earned 500 total points
ID: 21768612
No. You need a default to allow any as you do not know to which addresses you will be sending internet traffic. The closest you could probably be come would be:

permit YOUR networks
deny 10.x
deny 192.x
deny 172.x (basically put in deny rules for all PRIVATE subnets)
permit any (to allow access to the internet)
0
 

Author Closing Comment

by:Culbert
ID: 31466166
Thanks for your help.  Its working.
0

Featured Post

How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

Join & Write a Comment

There are some basic methods for preventing attacks on, hacking of and unauthorized access to a network -- maybe not completely, but up to a certain level. Start with a well-reputed firewall and unified threat management (UTM) system -- a gateway…
Hi All,  Recently I have installed and configured a Sonicwall NS220 in the network as a firewall and Internet access gateway. All was working fine until users started reporting that they cannot use the Cisco VPN client to connect to the customer'…
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…
When you create an app prototype with Adobe XD, you can insert system screens -- sharing or Control Center, for example -- with just a few clicks. This video shows you how. You can take the full course on Experts Exchange at http://bit.ly/XDcourse.

757 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

20 Experts available now in Live!

Get 1:1 Help Now