Solved

applying Access lists

Posted on 2008-06-25
9
218 Views
Last Modified: 2011-10-19
If I understand:

When applying access list to interfaces, we apply the standard access list at the destination interface
 we apply the extended access list at source interface or may be both.

Router(config-if)# ip access-group  AccessListName out

My question is:
- if we have 2 routers routerA and RouterB both have 3 interfaces, but dierectly connected through one interface.
we need to apply an  access lists to block SMTP traffic  from router A to routerB
an we need to block all traffic from host 192.168.1.45 located  behind routerB network and going to routerA


how can we configure access lists?

thanks
0
Comment
Question by:jskfan
  • 5
  • 4
9 Comments
 
LVL 50

Expert Comment

by:Don Johnston
ID: 21864472
If all you're trying to do is control access on the link between the two routers, then you could apply the standard ACL outbound on one router and the extended ACL inbound on the other.
0
 

Author Comment

by:jskfan
ID: 21865762
Here is the diagram:

Router.bmp
0
 

Author Comment

by:jskfan
ID: 21870152
we need to apply an  access lists to block SMTP traffic  from router1 to router2
an we need to block all traffic from host 192.168.1.45 located  behind router2 network and going to router1.
how do you write the command line to acieve that?

0
Create the perfect environment for any meeting

You might have a modern environment with all sorts of high-tech equipment, but what makes it worthwhile is how you seamlessly bring together the presentation with audio, video and lighting. The ATEN Control System provides integrated control and system automation.

 
LVL 50

Accepted Solution

by:
Don Johnston earned 500 total points
ID: 21870212
The following would be done on Router 1

access-list 1 deny 192.168.1.45 0.0.0.0
access-list 1 permit any
access-list 101 deny tcp any any eq 25
access-list 101 permit ip any any
!
int e2
 ip access-group 101 out
 ip access-group 1 in

Open in new window

0
 

Author Comment

by:jskfan
ID: 21871375
could you please specufy whic int e2 are you applying the access lists to? is it the e2 on router1 or e2 on router2?

0
 
LVL 50

Expert Comment

by:Don Johnston
ID: 21873737
A router can only have one ethernet 2 interface.
0
 

Author Comment

by:jskfan
ID: 21874553
in the diagram both routers have e0,e1,e2
can you tell me to which e2 didi you apply the access list?
0
 
LVL 50

Expert Comment

by:Don Johnston
ID: 21880278
If you look at my comment where I posted the config, you will see "The following would be done on Router 1"


0
 

Author Comment

by:jskfan
ID: 21880545
sorry I did not see it.

The purpose of posting this question was to understand when and where to use the "in" and "out " at the interface level.

in your case you applied  :
Extended access list at the source router Router1 (e2) to prevent any SMTP traffic to go to Router2
Standard Access list at the destination router Router1 (e2) to prevent the traffic from 192.168.1.45  to come in through e2.
Is there any rule to follow in order to know to which interface the access list should be applied to?

0

Featured Post

Free Tool: Subnet Calculator

The subnet calculator helps you design networks by taking an IP address and network mask and returning information such as network, broadcast address, and host range.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Problem Description:   Couple of months ago we upgraded the ADSL line at our branch office from Home to Business line. The purpose of transforming the service to have static public IP’s. We were in need for public IP’s to publish our web resour…
In the hope of saving someone else's sanity... About a year ago we bought a Cisco 1921 router with two ADSL/VDSL EHWIC cards to load balance local network traffic over the two broadband lines we have, but we couldn't get the routing to work consi…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

828 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question