Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

How do I block access to specific ip range in Cisco Router

Posted on 2011-09-05
2
Medium Priority
?
571 Views
Last Modified: 2012-08-13
I need to block access from 192.168.2.1-255 to 192.168.1.1-255 and vice versa on a cisco C2600 (C2600-ENTBASE-M), Version 12.4(5).

I managed to get something working but I when pinging, i get a message that I don't want
Communication prohibited by filter

I do however want to get this message instead, as if the host does not even exist
Request timeout for icmp_seq 1

interface FastEthernet0/1
 no ip address
 duplex auto
 speed auto
!
interface FastEthernet0/1.5
 encapsulation dot1Q 5 native
 ip address 192.168.2.254 255.255.255.0
 ip access-group 100 in
 ip nat inside
 no snmp trap link-status
!
interface FastEthernet0/1.6
 encapsulation dot1Q 6
 ip address 192.168.1.1 255.255.255.0
 ip access-group 101 in
 ip nat inside
 no snmp trap link-status
!

...

!
access-list 1 permit 192.168.1.0 0.0.0.255
access-list 1 permit 192.168.2.0 0.0.0.255
!
access-list 100 remark ACL For LAN Network
access-list 100 deny   ip any 192.168.1.0 0.0.0.255
access-list 100 permit ip any any
!
access-list 101 remark ACL For GUEST Network
access-list 101 deny   ip any 192.168.2.0 0.0.0.255
access-list 101 permit ip any any
!

Open in new window

0
Comment
Question by:Alex_Calcan
2 Comments
 
LVL 35

Accepted Solution

by:
Ernie Beek earned 2000 total points
ID: 36483523
You could try to set: no ip unreachables on the interface.
0
 
LVL 1

Author Closing Comment

by:Alex_Calcan
ID: 36483601
Thank you!
0

Featured Post

Veeam and MySQL: How to Perform Backup & Recovery

MySQL and the MariaDB variant are among the most used databases in Linux environments, and many critical applications support their data on them. Watch this recorded webinar to find out how Veeam Backup & Replication allows you to get consistent backups of MySQL databases.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

For months I had no idea how to 'discover' the IP address of the other end of a link (without asking someone who knows), and it drove me batty. Think about it. You can't use Cisco Discovery Protocol (CDP) because it's not implemented on the ASAs.…
In this article, the configuration steps in Zabbix to monitor devices via SNMP will be discussed with some real examples on Cisco Router/Switch, Catalyst Switch, NAS Synology device.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …

824 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question