We help IT Professionals succeed at work.

Access-list smtp

kitbarr
kitbarr asked
on
755 Views
Last Modified: 2013-11-30
When I apply this acl to the external interface connected to the internet it breaks all traffic.

int ser 0/0/0
ip access-group 101 in

Any ideas?
Extended IP access list 101
    10 permit tcp 0.0.0.0 0.0.3.255 0.0.0.0 0.0.0.3 eq smtp
    20 permit tcp 0.0.0.0 0.0.7.255 0.0.0.0 0.0.0.3 eq smtp
    30 deny tcp any any eq smtp

Open in new window

Comment
Watch Question

what are you trying to do? use the access list to only permit SMTP traffic or you want http/https traffic to pass through also?
Top Expert 2009

Commented:
Add permit ip any any at the bottom since there is any implicit "deny all" at the end.

permit tcp 0.0.0.0 0.0.3.255 0.0.0.0 0.0.0.3 eq smtp
permit tcp 0.0.0.0 0.0.7.255 0.0.0.0 0.0.0.3 eq smtp
deny tcp any any eq smtp
permit ip any any

Author

Commented:
adding permit ip any any allows traffic to flow however the deny tcp any any eq smtp seems to be catching all smtp traffic. the first two lines don't seem to be working.
what are you trying to do?
permit SMTP traffic from one host out to the internet but block any SMTP traffic from coming out from another machine?

Author

Commented:
I want to allow all smtp traffic out however only allow smtp traffic in from mx logic. 208.65.144.0/21 and 208.81.64.0/22 is what I am trying to allow in.

Author

Commented:
Yes and I would also like to allow all other http traffic. I'm only trying to block smtp from the outside in.

Author

Commented:
This is what it looks like right now
GWAQUA(config-ext-nacl)#do sh access-list
Extended IP access list 102
    40 permit ip any any (600928 matches)

Open in new window

This one is on us!
(Get your first solution completely free - no credit card required)
UNLOCK SOLUTION

Author

Commented:
That worked perfectly. What is the difference between
access-list 101 permit tcp 0.0.0.0 0.0.3.255 eq smtp any eq smtp and
access-list 101 permit tcp 208.65.144.0 0.0.3.255 any eq smtp

Author

Commented:
This person kept right on at answering my questions as we went. Solved my problem and also helped me understand a little bit more.
permit tcp 0.0.0.0 0.0.3.255 0.0.0.0 0.0.0.3 eq smtp
that is saying permit traffic from any host in the 255.255.252.0 subnet going to any host in the 255.255.255.252 subnet

access-list 101 permit tcp 208.65.144.0 0.0.3.255 any eq smtp
this is more specifically saying permit from the 208.65.144.0/22 network to any host in your network

Glad to help!

Gain unlimited access to on-demand training courses with an Experts Exchange subscription.

Get Access
Why Experts Exchange?

Experts Exchange always has the answer, or at the least points me in the correct direction! It is like having another employee that is extremely experienced.

Jim Murphy
Programmer at Smart IT Solutions

When asked, what has been your best career decision?

Deciding to stick with EE.

Mohamed Asif
Technical Department Head

Being involved with EE helped me to grow personally and professionally.

Carl Webster
CTP, Sr Infrastructure Consultant
Empower Your Career
Did You Know?

We've partnered with two important charities to provide clean water and computer science education to those who need it most. READ MORE

Ask ANY Question

Connect with Certified Experts to gain insight and support on specific technology challenges including:

  • Troubleshooting
  • Research
  • Professional Opinions
Unlock the solution to this question.
Join our community and discover your potential

Experts Exchange is the only place where you can interact directly with leading experts in the technology field. Become a member today and access the collective knowledge of thousands of technology experts.

*This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

OR

Please enter a first name

Please enter a last name

8+ characters (letters, numbers, and a symbol)

By clicking, you agree to the Terms of Use and Privacy Policy.