Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

Cisco 2911 blocking external addresses

Posted on 2011-03-02
9
Medium Priority
?
1,272 Views
Last Modified: 2012-05-11
Hi
I need to block a couple of external IP's via my acl, need help with the commands.  If I put 1,2,3 infornt of these commands then my other permit commands come in the way, also undermentioned commands needs to be tweaked, as my router do not accept them:
Example:

ip access-list extended 101
1 access-list 109 deny ip 72.26.98.0 0.0.0.8 any
2 access-list 109 deny ip host 72.26.98.8 any
3 access-list 109 deny ip host 72.26.98.9 any
4 access-list 109 deny ip host 72.26.98.10 any


  Attached is my ACL.  Also I would like to put the commands in a manner so that I can easily add more and remove anyone anytime. Help plz.
forEEpuposesAccesslistNewFeb2011.txt
0
Comment
Question by:amanzoor
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 5
  • 4
9 Comments
 
LVL 34

Accepted Solution

by:
Istvan Kalmar earned 2000 total points
ID: 35017258
Hi,

you need to reapply to the interface:

interface GigabitEthernet0/1.92
 access-group 101 in
0
 
LVL 4

Author Comment

by:amanzoor
ID: 35017493
ikalmar:
Here is what I am doing:

__2911(config)#ip acc
__2911(config)#ip acce
__2911(config)#ip access-li
__2911(config)#ip access-list e
__2911(config)#ip access-list extended 101
__2911(config-ext-nacl)#1 access
__2911(config-ext-nacl)#1 access-l
__2911(config-ext-nacl)#1 access-l
__2911(config-ext-nacl)#1 access-li
__2911(config-ext-nacl)#1 access-list 109 ?
% Unrecognized command
__2911(config-ext-nacl)#1 access-list 109

Help
0
 
LVL 4

Author Comment

by:amanzoor
ID: 35017700
ikalmar:
If I apply access-group 109 in to my external interface it simply replaces my existing access-group 101?   How many access-groups can I apply to my external interfaces.
0
Plug and play, no additional software required!

The ATEN UE3310 USB3.1 Gen1 Extender Cable allows users to extend the distance between the computer and USB devices up to 10 m (33 ft). The UE3310 is a high-quality, cost-effective solution for professional environments such as hospitals, factories and business facilities.

 
LVL 34

Expert Comment

by:Istvan Kalmar
ID: 35017882
oh you need:

ip access-list extended 101
1 permit xxxxxxxxx
2 permit xxxxxxxxx


ip access-list command not need after you get ip access-list ......
0
 
LVL 34

Expert Comment

by:Istvan Kalmar
ID: 35017983
only on access-group can be applied for an interface!
0
 
LVL 4

Author Comment

by:amanzoor
ID: 35018015
Thanks ikalmar:
can I change the serial number because if I have more than 10 addresses than my existing permit or deny comes in the way?

Extended IP access list 101
    10 deny ip 10.0.0.0 0.255.255.255 any (1356 matches)
    20 permit icmp any any echo (110137 matches)
    30 permit icmp any any unreachable (91882 matches)
    40 permit icmp any any traceroute
    50 permit icmp any any echo-reply
    60 permit icmp any any ttl-exceeded (2723 matches)
    70 permit icmp any any time-exceeded
    80 permit icmp any any source-quench (143 matches)
    90 permit icmp any any packet-too-big
    100 permit ip any host X>X>X>X> (26195993 matches)
    110 permit tcp any host x.x.x.x.x eq www (17879 matches)
    120 permit tcp any host x.x.x.x.x eq www (42 matches)
    130 permit tcp any host
0
 
LVL 34

Assisted Solution

by:Istvan Kalmar
Istvan Kalmar earned 2000 total points
ID: 35018197
no you not able to change sequence number only that you delete the row, for example:

ip access-list 101 extended
 no 10 deny ip 10.0.0.0 0.255.255.255 any
 19 deny ip 10.0.0.0 0.255.255.255 any  


Best regards,
Istvan
0
 
LVL 4

Author Comment

by:amanzoor
ID: 35018766
so it means the deny entries have to come on top of the 101 list ?
0
 
LVL 4

Author Closing Comment

by:amanzoor
ID: 35028078
THanks IKalmar for your support I really appreciate it.
0

Featured Post

[Webinar] Lessons on Recovering from Petya

Skyport is working hard to help customers recover from recent attacks, like the Petya worm. This work has brought to light some important lessons. New malware attacks like this can take down your entire environment. Learn from others mistakes on how to prevent Petya like worms.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This tutorial will go through the steps required to write a script that will back up the configuration settings of a HP-ProCurve switch. You will need to get the following things to follow this tutorial: Telnet Scripting Tool e.g. TST10.exe …
There are two basic ways to configure a static route for Cisco IOS devices. I've written this article to highlight a case study comparing the configuration of a static route using the next-hop IP and the configuration of a static route using an outg…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

705 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question