Solved

Cisco 2911 blocking external addresses

Posted on 2011-03-02
9
1,255 Views
Last Modified: 2012-05-11
Hi
I need to block a couple of external IP's via my acl, need help with the commands.  If I put 1,2,3 infornt of these commands then my other permit commands come in the way, also undermentioned commands needs to be tweaked, as my router do not accept them:
Example:

ip access-list extended 101
1 access-list 109 deny ip 72.26.98.0 0.0.0.8 any
2 access-list 109 deny ip host 72.26.98.8 any
3 access-list 109 deny ip host 72.26.98.9 any
4 access-list 109 deny ip host 72.26.98.10 any


  Attached is my ACL.  Also I would like to put the commands in a manner so that I can easily add more and remove anyone anytime. Help plz.
forEEpuposesAccesslistNewFeb2011.txt
0
Comment
Question by:amanzoor
  • 5
  • 4
9 Comments
 
LVL 34

Accepted Solution

by:
Istvan Kalmar earned 500 total points
ID: 35017258
Hi,

you need to reapply to the interface:

interface GigabitEthernet0/1.92
 access-group 101 in
0
 
LVL 4

Author Comment

by:amanzoor
ID: 35017493
ikalmar:
Here is what I am doing:

__2911(config)#ip acc
__2911(config)#ip acce
__2911(config)#ip access-li
__2911(config)#ip access-list e
__2911(config)#ip access-list extended 101
__2911(config-ext-nacl)#1 access
__2911(config-ext-nacl)#1 access-l
__2911(config-ext-nacl)#1 access-l
__2911(config-ext-nacl)#1 access-li
__2911(config-ext-nacl)#1 access-list 109 ?
% Unrecognized command
__2911(config-ext-nacl)#1 access-list 109

Help
0
 
LVL 4

Author Comment

by:amanzoor
ID: 35017700
ikalmar:
If I apply access-group 109 in to my external interface it simply replaces my existing access-group 101?   How many access-groups can I apply to my external interfaces.
0
 
LVL 34

Expert Comment

by:Istvan Kalmar
ID: 35017882
oh you need:

ip access-list extended 101
1 permit xxxxxxxxx
2 permit xxxxxxxxx


ip access-list command not need after you get ip access-list ......
0
How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

 
LVL 34

Expert Comment

by:Istvan Kalmar
ID: 35017983
only on access-group can be applied for an interface!
0
 
LVL 4

Author Comment

by:amanzoor
ID: 35018015
Thanks ikalmar:
can I change the serial number because if I have more than 10 addresses than my existing permit or deny comes in the way?

Extended IP access list 101
    10 deny ip 10.0.0.0 0.255.255.255 any (1356 matches)
    20 permit icmp any any echo (110137 matches)
    30 permit icmp any any unreachable (91882 matches)
    40 permit icmp any any traceroute
    50 permit icmp any any echo-reply
    60 permit icmp any any ttl-exceeded (2723 matches)
    70 permit icmp any any time-exceeded
    80 permit icmp any any source-quench (143 matches)
    90 permit icmp any any packet-too-big
    100 permit ip any host X>X>X>X> (26195993 matches)
    110 permit tcp any host x.x.x.x.x eq www (17879 matches)
    120 permit tcp any host x.x.x.x.x eq www (42 matches)
    130 permit tcp any host
0
 
LVL 34

Assisted Solution

by:Istvan Kalmar
Istvan Kalmar earned 500 total points
ID: 35018197
no you not able to change sequence number only that you delete the row, for example:

ip access-list 101 extended
 no 10 deny ip 10.0.0.0 0.255.255.255 any
 19 deny ip 10.0.0.0 0.255.255.255 any  


Best regards,
Istvan
0
 
LVL 4

Author Comment

by:amanzoor
ID: 35018766
so it means the deny entries have to come on top of the 101 list ?
0
 
LVL 4

Author Closing Comment

by:amanzoor
ID: 35028078
THanks IKalmar for your support I really appreciate it.
0

Featured Post

Maximize Your Threat Intelligence Reporting

Reporting is one of the most important and least talked about aspects of a world-class threat intelligence program. Here’s how to do it right.

Join & Write a Comment

Suggested Solutions

Problem Description:   Couple of months ago we upgraded the ADSL line at our branch office from Home to Business line. The purpose of transforming the service to have static public IP’s. We were in need for public IP’s to publish our web resour…
Getting hacked is no longer a matter or "if you get hacked" — the 2016 cyber threat landscape is now titled "when you get hacked." When it happens — will you be proactive, or reactive?
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

708 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

18 Experts available now in Live!

Get 1:1 Help Now