Solved

Cisco 2911 Access list

Posted on 2011-03-10
5
997 Views
Last Modified: 2012-05-11
Hi I am putting the entry for NAS cisco 324 (ip 10.10.10.80)  in the router 2911:

what's up with the routers ACL:
I put
ip nat inside source static 10.10.10.80 X.X.X.X  <<<.......Even if I put only this entry it opens up ports 8080,8081, 80 etc

and then under my access-list 101 I put:
permit tcp any host X.X.X.X eq 8080

How to manipulate the entry so that only port 8080 is allowed
NOte: since NAS 324 has its own web server, multimedia server its doing something of its on.

Help
forEEpuposesAccesslistNewFeb2011.txt
0
Comment
Question by:amanzoor
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
5 Comments
 
LVL 5

Accepted Solution

by:
evil_hitman earned 450 total points
ID: 35099739
2 options
change your nat statement to only be for the one port. eg.
ip nat inside source static tcp 10.10.10.80 8080 X.X.X.X 8080

or

to use your access list you need to apply it to an interface.
Based on the way you have written the rules i would put it inbound on the internet interface so.....

interface GigabitEthernet0/1.92
ip access-group 101 in

make sure you aren't connected via this interface when you add the rule in case you lose connectivity.
0
 
LVL 4

Author Comment

by:amanzoor
ID: 35100018
evil hitman:
through which command I can actually see if my applied settings for this particular ip have been applied and working?  I have just applied your first suggested option.  I need to find out if it actually is working on the router .
Help
0
 
LVL 5

Expert Comment

by:evil_hitman
ID: 35100409
for the first option, you check it is in the config (and make sure you have removed the other nat config line relating to that ip) then see if you can do anything other than 8080

you can do the following command

show ip nat translations

but this will give you massive output and will probably not be of much use in a live environment, There are some other options you can add to that command but i don't remember them off the top of my head. type ? to get a list of options as you are typing the command

0
 
LVL 3

Assisted Solution

by:alexjfisher
alexjfisher earned 50 total points
ID: 35101514
Your 101 access list isn't applied to any interface.

You must choose the most appropriate interface and direction to apply the access-list to.
Perhaps inbound on your internet facing interface or possibly outbound on the interface closest to the NAS.

Also remember that access-lists are evaluated in order.  The first match found wins.  If no access-list statement is matched by the end of the list there's an implicit deny all.

0
 
LVL 4

Author Closing Comment

by:amanzoor
ID: 35110910
THanks guys for the suggestions, I really appreciate your time.
I opted for option 2: and it worked falwless.
0

Featured Post

Portable, direct connect server access

The ATEN CV211 connects a laptop directly to any server allowing you instant access to perform data maintenance and local operations, for quick troubleshooting, updating, service and repair.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Forwarding web requests to different web servers 15 216
Usage of Prefix-List 5 73
Understanding Extended-Access List 6 72
can you connect modem to 2 routers 42 19
While it is possible to put two routes in place with the secondary having a higher metric, this may not always work. In the event of a failure that does not bring down the physical interface on the router the primary route is not removed. There is a…
In the world of WAN, QoS is a pretty important topic for most, if not all, networks. Some WAN technologies have QoS mechanisms built in, but others, such as some L2 WAN's, don't have QoS control in the provider cloud.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

740 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question