Solved

Cisco 2911 blocking external addresses

Posted on 2011-03-02
9
1,269 Views
Last Modified: 2012-05-11
Hi
I need to block a couple of external IP's via my acl, need help with the commands.  If I put 1,2,3 infornt of these commands then my other permit commands come in the way, also undermentioned commands needs to be tweaked, as my router do not accept them:
Example:

ip access-list extended 101
1 access-list 109 deny ip 72.26.98.0 0.0.0.8 any
2 access-list 109 deny ip host 72.26.98.8 any
3 access-list 109 deny ip host 72.26.98.9 any
4 access-list 109 deny ip host 72.26.98.10 any


  Attached is my ACL.  Also I would like to put the commands in a manner so that I can easily add more and remove anyone anytime. Help plz.
forEEpuposesAccesslistNewFeb2011.txt
0
Comment
Question by:amanzoor
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 5
  • 4
9 Comments
 
LVL 34

Accepted Solution

by:
Istvan Kalmar earned 500 total points
ID: 35017258
Hi,

you need to reapply to the interface:

interface GigabitEthernet0/1.92
 access-group 101 in
0
 
LVL 4

Author Comment

by:amanzoor
ID: 35017493
ikalmar:
Here is what I am doing:

__2911(config)#ip acc
__2911(config)#ip acce
__2911(config)#ip access-li
__2911(config)#ip access-list e
__2911(config)#ip access-list extended 101
__2911(config-ext-nacl)#1 access
__2911(config-ext-nacl)#1 access-l
__2911(config-ext-nacl)#1 access-l
__2911(config-ext-nacl)#1 access-li
__2911(config-ext-nacl)#1 access-list 109 ?
% Unrecognized command
__2911(config-ext-nacl)#1 access-list 109

Help
0
 
LVL 4

Author Comment

by:amanzoor
ID: 35017700
ikalmar:
If I apply access-group 109 in to my external interface it simply replaces my existing access-group 101?   How many access-groups can I apply to my external interfaces.
0
Optimum High-Definition Video Viewing and Control

The ATEN VM0404HA 4x4 4K HDMI Matrix Switch supports 4K resolutions of UHD (3840 x 2160) and DCI (4096 x 2160) with refresh rates of 30 Hz (4:4:4) and 60 Hz (4:2:0). It is ideal for applications where the routing of 4K digital signals is required.

 
LVL 34

Expert Comment

by:Istvan Kalmar
ID: 35017882
oh you need:

ip access-list extended 101
1 permit xxxxxxxxx
2 permit xxxxxxxxx


ip access-list command not need after you get ip access-list ......
0
 
LVL 34

Expert Comment

by:Istvan Kalmar
ID: 35017983
only on access-group can be applied for an interface!
0
 
LVL 4

Author Comment

by:amanzoor
ID: 35018015
Thanks ikalmar:
can I change the serial number because if I have more than 10 addresses than my existing permit or deny comes in the way?

Extended IP access list 101
    10 deny ip 10.0.0.0 0.255.255.255 any (1356 matches)
    20 permit icmp any any echo (110137 matches)
    30 permit icmp any any unreachable (91882 matches)
    40 permit icmp any any traceroute
    50 permit icmp any any echo-reply
    60 permit icmp any any ttl-exceeded (2723 matches)
    70 permit icmp any any time-exceeded
    80 permit icmp any any source-quench (143 matches)
    90 permit icmp any any packet-too-big
    100 permit ip any host X>X>X>X> (26195993 matches)
    110 permit tcp any host x.x.x.x.x eq www (17879 matches)
    120 permit tcp any host x.x.x.x.x eq www (42 matches)
    130 permit tcp any host
0
 
LVL 34

Assisted Solution

by:Istvan Kalmar
Istvan Kalmar earned 500 total points
ID: 35018197
no you not able to change sequence number only that you delete the row, for example:

ip access-list 101 extended
 no 10 deny ip 10.0.0.0 0.255.255.255 any
 19 deny ip 10.0.0.0 0.255.255.255 any  


Best regards,
Istvan
0
 
LVL 4

Author Comment

by:amanzoor
ID: 35018766
so it means the deny entries have to come on top of the 101 list ?
0
 
LVL 4

Author Closing Comment

by:amanzoor
ID: 35028078
THanks IKalmar for your support I really appreciate it.
0

Featured Post

VIDEO: THE CONCERTO CLOUD FOR HEALTHCARE

Modern healthcare requires a modern cloud. View this brief video to understand how the Concerto Cloud for Healthcare can help your organization.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Tired of waiting for your show or movie to load?  Are buffering issues a constant problem with your internet connection?  Check this article out to see if these simple adjustments are the solution for you.
WARNING:   If you follow the instructions here, you will wipe out your VTP and VLAN configurations.  Make sure you have backed up your switch!!! I recently had some issues with a few low-end Cisco routers (RV325) and I opened a case with Cisco TA…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Suggested Courses
Course of the Month7 days, 17 hours left to enroll

617 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question