Solved

Frustrating Cisco Access list problom

Posted on 2008-06-23
3
830 Views
Last Modified: 2012-05-05
Hi,

I have a router up and running, I am just trying to add a access list rule to allow TFTP (for backing up IOS etc),
It sounds simple but I cannot get it to work, spent ages fiddling around now, it works if i disable the access list from the dilaer interface so i know it where the problem is, enclosed is the config for the affected areas,

interface Dialer1
 bandwidth 800
 ip address negotiated
 ip nat outside
 ip inspect swd out
 ip access-group 111 in
 ip virtual-reassembly
 encapsulation ppp
 dialer pool 1
 dialer-group 1
 no cdp enable
 ppp authentication chap pap callin
 ppp chap hostname xxxxxxxxxxxxxxxxxxx
 ppp chap password xxxxxxxxxxxxxxxxxxx
 ppp pap sent-username xxxxxxxxxxxxxxxxxx password xxxxxxxxxxx
 service-policy output qos-policy
 hold-queue 224 in



access-list 111 permit esp any any
access-list 111 permit udp any eq domain any
access-list 111 permit tcp any eq domain any
access-list 111 permit gre any any
access-list 111 permit udp any any eq isakmp
access-list 111 permit icmp any any echo
access-list 111 permit icmp any any echo-reply
access-list 111 permit tcp any any eq 1723
access-list 111 permit udp any any eq 1723
access-list 111 permit tcp host 1.1.1.1 host 2.2.2.2 eq 22
access-list 111 permit tcp host 1.1.1.1 host 2.2.2.2 eq telnet
access-list 111 permit udp host 1.1.1.1 host 2.2.2.2 eq tftp
access-list 111 permit udp any any eq tftp
access-list 111 permit udp any any eq non500-isakmp
access-list 111 deny   ip any any log


1.1.1.1 is the remote device and 2.2.2.2 is the dilaer interface ip address, please help it's driving me nuts, to make matter worse the telnet and ssh rules work !!

Thanks guys
0
Comment
Question by:webleyaxsor
  • 2
3 Comments
 
LVL 50

Accepted Solution

by:
Don Johnston earned 250 total points
ID: 21845121
If you're backing up the IOS, then the router is communicating with the server. The responses will be coming FROM the TFTP server.

Change the line:
access-list 111 permit udp host 1.1.1.1 host 2.2.2.2 eq tftp

To read:
access-list 111 permit udp host 1.1.1.1 eq tftp host 2.2.2.2
0
 

Author Comment

by:webleyaxsor
ID: 21976269
thanks, worked a treat
0
 

Author Comment

by:webleyaxsor
ID: 21976296
thans for your help
0

Featured Post

Easy, flexible multimedia distribution & control

Coming soon!  Ideal for large-scale A/V applications, ATEN's VM3200 Modular Matrix Switch is an all-in-one solution that simplifies video wall integration. Easily customize display layouts to see what you want, how you want it in 4k.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

I have seen some questions on problems with SSH/telnet access to Cisco routers that may occur despite the fact that from a PC connected to your LAN, Internet connectivity is in place and users can access Internet sites without any issues.  There are…
Tired of waiting for your show or movie to load?  Are buffering issues a constant problem with your internet connection?  Check this article out to see if these simple adjustments are the solution for you.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

821 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question