Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 667
  • Last Modified:

Cisco ACL to allow internet access

Hello,
I have the following VLAN configuration:

interface Vlan3
 ip address 10.10.30.1 255.255.255.0
 ip access-group 130 in
 ip nat inside
 ip virtual-reassembly
!
access-list 130 permit tcp any any established
access-list 130 permit tcp any any www
access-list 130 permit tcp any any telnet
access-list 130 permit tcp any any smtp
access-list 130 permit tcp any any pop3

If I remove acl 130 from the VLAN, then I have access to the internet.  If I apply acl 130 to the VLAN (as shown above) then I can no longer access the internet from hosts on the VLAN.  What am I doing wrong and/or missing from the acl?

Thanks for the help.
0
P1ST0LPETE
Asked:
P1ST0LPETE
  • 4
1 Solution
 
P1ST0LPETEAuthor Commented:
Ooops, forgot to include the "eq" in those lines above.  So for example

access-list 130 permit tcp any any www

is actually

access-list 130 permit tcp any any eq www

in my config file.
0
 
Don JohnstonInstructorCommented:
Please post your actual configuration.
0
 
JFrederick29Commented:
Add this:

access-list 130 permit udp any any eq 53
0
Concerto Cloud for Software Providers & ISVs

Can Concerto Cloud Services help you focus on evolving your application offerings, while delivering the best cloud experience to your customers? From DevOps to revenue models and customer support, the answer is yes!

Learn how Concerto can help you.

 
P1ST0LPETEAuthor Commented:
Adding "access-list 130 permit udp any any eq 53" fixed the problem.  Why did that fix it?
0
 
P1ST0LPETEAuthor Commented:
Ah, nevermind.  I googled it.  It's allowing DNS traffic.
0
 
P1ST0LPETEAuthor Commented:
Thanks.
0

Featured Post

Who's Defending Your Organization from Threats?

Protecting against advanced threats requires an IT dream team – a well-oiled machine of people and solutions working together to defend your organization. Download our resource kit today to learn more about the tools you need to build you IT Dream Team!

  • 4
Tackle projects and never again get stuck behind a technical roadblock.
Join Now