Solved

How do I block access to specific ip range in Cisco Router

Posted on 2011-09-05
2
539 Views
Last Modified: 2012-08-13
I need to block access from 192.168.2.1-255 to 192.168.1.1-255 and vice versa on a cisco C2600 (C2600-ENTBASE-M), Version 12.4(5).

I managed to get something working but I when pinging, i get a message that I don't want
Communication prohibited by filter

I do however want to get this message instead, as if the host does not even exist
Request timeout for icmp_seq 1

interface FastEthernet0/1
 no ip address
 duplex auto
 speed auto
!
interface FastEthernet0/1.5
 encapsulation dot1Q 5 native
 ip address 192.168.2.254 255.255.255.0
 ip access-group 100 in
 ip nat inside
 no snmp trap link-status
!
interface FastEthernet0/1.6
 encapsulation dot1Q 6
 ip address 192.168.1.1 255.255.255.0
 ip access-group 101 in
 ip nat inside
 no snmp trap link-status
!

...

!
access-list 1 permit 192.168.1.0 0.0.0.255
access-list 1 permit 192.168.2.0 0.0.0.255
!
access-list 100 remark ACL For LAN Network
access-list 100 deny   ip any 192.168.1.0 0.0.0.255
access-list 100 permit ip any any
!
access-list 101 remark ACL For GUEST Network
access-list 101 deny   ip any 192.168.2.0 0.0.0.255
access-list 101 permit ip any any
!

Open in new window

0
Comment
Question by:Alex_Calcan
2 Comments
 
LVL 35

Accepted Solution

by:
Ernie Beek earned 500 total points
ID: 36483523
You could try to set: no ip unreachables on the interface.
0
 
LVL 1

Author Closing Comment

by:Alex_Calcan
ID: 36483601
Thank you!
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

The Cisco RV042 router is a popular small network interfacing device that is often used as an internet gateway. Network administrators need to get at the management interface to make settings, change passwords, etc. This access is generally done usi…
Getting hacked is no longer a matter or "if you get hacked" — the 2016 cyber threat landscape is now titled "when you get hacked." When it happens — will you be proactive, or reactive?
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…

911 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

17 Experts available now in Live!

Get 1:1 Help Now