Why Experts Exchange?

Experts Exchange always has the answer, or at the least points me in the correct direction! It is like having another employee that is extremely experienced.

Jim Murphy
Programmer at Smart IT Solutions

When asked, what has been your best career decision?

Deciding to stick with EE.

Mohamed Asif
Technical Department Head

Being involved with EE helped me to grow personally and professionally.

Carl Webster
CTP, Sr Infrastructure Consultant
Ask ANY Question

Connect with Certified Experts to gain insight and support on specific technology challenges including:

Troubleshooting
Research
Professional Opinions
Ask a Question
Did You Know?

We've partnered with two important charities to provide clean water and computer science education to those who need it most. READ MORE

troubleshooting Question

cisco access list help

Avatar of awilderbeast
awilderbeastFlag for United Kingdom of Great Britain and Northern Ireland asked on
RoutersNetworkingNetworking Hardware-OtherCisco
38 Comments1 Solution1029 ViewsLast Modified:
hi all below is my current inbound acl applied to my dialer interface with in direction

i have nat rules that forward all the traffic, smtp, https, http, mysql to the address 192.168.20.1 (my firewall)

but as you can see i have applied the acl INBOUND on my dialer int, and the matches arent giong up, ive even tested our website externally and the increments havent gone up

also u have gre tunnels on 192.168.100.0/248 so ive added
    80 permit udp 192.168.96.0 0.0.15.255 any eq isakmp
and those incements arent going up either

anyone help me out getting my acl working?

network goes

INTERNET------- VLAN 101 (192.168.101.0/24) - VLAN 201 (192.168.201.0/24) - TUNNEL 1 (192.168.100.0/24)
Extended IP access list INBOUND
    10 permit tcp 192.168.96.0 0.0.15.255 any eq 22
    20 permit tcp 172.30.0.0 0.0.7.255 any eq 22
    30 deny tcp any any eq 22 (8 matches)
    40 deny tcp any host 192.168.101.254 eq telnet
    50 deny tcp any host 192.168.201.254 eq telnet
    60 permit tcp 192.168.96.0 0.0.7.255 192.168.96.0 0.0.7.255 eq telnet
    70 deny tcp any any eq telnet
    80 permit udp 192.168.96.0 0.0.15.255 any eq isakmp
    90 permit tcp any host 192.168.201.1 eq www
    100 permit tcp any host 192.168.101.5 eq www
    110 permit tcp any host 192.168.201.1 eq 443
    120 permit tcp any host 192.168.101.5 eq 443
    130 permit tcp any host 192.168.201.1 eq 3306
    140 permit tcp any host 192.168.101.5 eq 3306
    150 permit tcp any host 192.168.201.1 eq smtp
    160 permit tcp any host 192.168.101.2 eq smtp
    170 permit ip any any (821805 matches)
ASKER CERTIFIED SOLUTION
Avatar of Jimmy Larsson, CISSP, CEH
Jimmy Larsson, CISSP, CEHFlag of Sweden imageNetwork and Security consultant

Our community of experts have been thoroughly vetted for their expertise and industry experience.

Commented:
This problem has been solved!
Unlock 1 Answer and 38 Comments.
See Answers