Solved

CCNA: Access-List from Outside to Inside

Posted on 2009-07-15
2
281 Views
Last Modified: 2012-05-07
Hi,

1) This is related to the CCNA Exam (but i want to apply it in a real life situation)
2) This is taken from one of the prep test.
3) Please see the attached file.
4) Tha given question: " What must be configured on the network in order for users on the internet to view web Pages located on the Web Server 2 ?.
5) The given answer: " On Router R1, Configure NAT to translate an address on the 209.165.100.0/24 network to 192.168.1.10
6) My question: i) I agree with the given answer, and i want to write it down the ios command for it , ii) I am still not yet confident related to this and i need the Confirmation or Correction from the experts related to it (Please see my ios commands below).

The IOS commands per my understanding:
R1(config)#interface fa0/0
R1(config-if)#ip nat inside
R1(config-if)#exit
R1(config)#interface s0/0/0
R1(config-if)#ip nat outside
R1(config-if)#exit
R1(config)#access-list 102 permit tcp 209.165.100.0 0.0.0.25 192.168.1.10 0.0.0.0 eq 80
R1(config)#access-list 102 deny any
R1(config)#ip nat inside source list 102 interface s0/0/0 overload

7)Thank you

tjie


ACL-fr-Outside001.jpg
0
Comment
Question by:tjie
2 Comments
 
LVL 5

Accepted Solution

by:
Ahmed Ezzat AbuRaya earned 300 total points
ID: 24865283
I think it is almost correct.. Maybe this is what you need:
Why don't you try experimenting using a simulator like Boson? It's great for CCNA..

R1(config)#interface fa0/0
*R1(config)#ip address 192.168.1.250 255.255.255.0
R1(config-if)#ip nat inside
R1(config-if)#exit
R1(config)#interface s0/0/0
*R1(config)#ip address 209.165.100.250 255.255.255.0
R1(config-if)#ip nat outside
R1(config-if)#exit
*R1(config)#access-list 102 permit tcp 209.165.100.0 0.0.0.255 192.168.1.10 0.0.0.0 eq 80
R1(config)#access-list 102 deny any
R1(config)#ip nat inside source list 102 interface s0/0/0 overload


Also check this: http://www.cisco.com/en/US/tech/tk648/tk361/technologies_tech_note09186a0080094e77.shtml

I Hope this helped. I'd be happy to see other comments from other experts :)
0
 
LVL 79

Assisted Solution

by:lrmoore
lrmoore earned 200 total points
ID: 24865823
The first part is correct, but here I would make changes

no:
R1(config)#access-list 102 permit tcp 209.165.100.0 0.0.0.25 192.168.1.10 0.0.0.0 eq 80
R1(config)#access-list 102 deny any
R1(config)#ip nat inside source list 102 interface s0/0/0 overload

Yes:
R1(config)#access-list 102 permit ip 192.168.1.0 0.0.0.255 any
R1(config)#ip nat inside source list 102 interface s0/0/0 overload
R1(config)#ip nat inside source tcp 192.168.1.10 80 interface ser0/0/0 80
0

Featured Post

Announcing the Most Valuable Experts of 2016

MVEs are more concerned with the satisfaction of those they help than with the considerable points they can earn. They are the types of people you feel privileged to call colleagues. Join us in honoring this amazing group of Experts.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

The Cisco RV042 router is a popular small network interfacing device that is often used as an internet gateway. Network administrators need to get at the management interface to make settings, change passwords, etc. This access is generally done usi…
Creating an OSPF network that automatically (dynamically) reroutes network traffic over other connections to prevent network downtime.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

816 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

13 Experts available now in Live!

Get 1:1 Help Now