Solved

Cisco 2911 blocking external addresses

Posted on 2011-03-02
9
1,267 Views
Last Modified: 2012-05-11
Hi
I need to block a couple of external IP's via my acl, need help with the commands.  If I put 1,2,3 infornt of these commands then my other permit commands come in the way, also undermentioned commands needs to be tweaked, as my router do not accept them:
Example:

ip access-list extended 101
1 access-list 109 deny ip 72.26.98.0 0.0.0.8 any
2 access-list 109 deny ip host 72.26.98.8 any
3 access-list 109 deny ip host 72.26.98.9 any
4 access-list 109 deny ip host 72.26.98.10 any


  Attached is my ACL.  Also I would like to put the commands in a manner so that I can easily add more and remove anyone anytime. Help plz.
forEEpuposesAccesslistNewFeb2011.txt
0
Comment
Question by:amanzoor
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 5
  • 4
9 Comments
 
LVL 34

Accepted Solution

by:
Istvan Kalmar earned 500 total points
ID: 35017258
Hi,

you need to reapply to the interface:

interface GigabitEthernet0/1.92
 access-group 101 in
0
 
LVL 4

Author Comment

by:amanzoor
ID: 35017493
ikalmar:
Here is what I am doing:

__2911(config)#ip acc
__2911(config)#ip acce
__2911(config)#ip access-li
__2911(config)#ip access-list e
__2911(config)#ip access-list extended 101
__2911(config-ext-nacl)#1 access
__2911(config-ext-nacl)#1 access-l
__2911(config-ext-nacl)#1 access-l
__2911(config-ext-nacl)#1 access-li
__2911(config-ext-nacl)#1 access-list 109 ?
% Unrecognized command
__2911(config-ext-nacl)#1 access-list 109

Help
0
 
LVL 4

Author Comment

by:amanzoor
ID: 35017700
ikalmar:
If I apply access-group 109 in to my external interface it simply replaces my existing access-group 101?   How many access-groups can I apply to my external interfaces.
0
Building an interactive eFuture classroom

Watch and learn how ATEN provided a total control system solution including seamless switching matrix switch, HDBaseT extenders, PDU, lighting control to build an interactive eFuture classroom.

 
LVL 34

Expert Comment

by:Istvan Kalmar
ID: 35017882
oh you need:

ip access-list extended 101
1 permit xxxxxxxxx
2 permit xxxxxxxxx


ip access-list command not need after you get ip access-list ......
0
 
LVL 34

Expert Comment

by:Istvan Kalmar
ID: 35017983
only on access-group can be applied for an interface!
0
 
LVL 4

Author Comment

by:amanzoor
ID: 35018015
Thanks ikalmar:
can I change the serial number because if I have more than 10 addresses than my existing permit or deny comes in the way?

Extended IP access list 101
    10 deny ip 10.0.0.0 0.255.255.255 any (1356 matches)
    20 permit icmp any any echo (110137 matches)
    30 permit icmp any any unreachable (91882 matches)
    40 permit icmp any any traceroute
    50 permit icmp any any echo-reply
    60 permit icmp any any ttl-exceeded (2723 matches)
    70 permit icmp any any time-exceeded
    80 permit icmp any any source-quench (143 matches)
    90 permit icmp any any packet-too-big
    100 permit ip any host X>X>X>X> (26195993 matches)
    110 permit tcp any host x.x.x.x.x eq www (17879 matches)
    120 permit tcp any host x.x.x.x.x eq www (42 matches)
    130 permit tcp any host
0
 
LVL 34

Assisted Solution

by:Istvan Kalmar
Istvan Kalmar earned 500 total points
ID: 35018197
no you not able to change sequence number only that you delete the row, for example:

ip access-list 101 extended
 no 10 deny ip 10.0.0.0 0.255.255.255 any
 19 deny ip 10.0.0.0 0.255.255.255 any  


Best regards,
Istvan
0
 
LVL 4

Author Comment

by:amanzoor
ID: 35018766
so it means the deny entries have to come on top of the 101 list ?
0
 
LVL 4

Author Closing Comment

by:amanzoor
ID: 35028078
THanks IKalmar for your support I really appreciate it.
0

Featured Post

Free Tool: IP Lookup

Get more info about an IP address or domain name, such as organization, abuse contacts and geolocation.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
replacing 2811 to ISR 4331 2 81
Provide internet access from one windows PC to another 16 149
Static Route on Cisco ISR 4431's 4 58
Mac address in Nexus7K fex port 5 46
This article is a guide to configure bridging on Cisco Routers.  This is something I never knew was possible until after making a few phone calls to Cisco.  Using bridging saved our company money by not requiring us to purchase a new switch.  Bridgi…
I recently attended Cisco Live! in Las Vegas, a conference that boasted over 28,000 techies in attendance, and a week of hands-on learning hosted by a solid partner with which Concerto goes to market.  Every year, Cisco displays cutting-edge technol…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

751 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question