Cisco 3560 ACL

I have not used ACL's much, so not sure the way to do this without a lot of playing.  I have a 3560, with a VLAN 905.  I'd like to make it so that all inbound traffic from my default gateway is blocked.

I basically want to block all Internet access on this VLAN.  I know this is pretty simply, but don't know the exact commands.

Thanks.

RailroadAsked:
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

x
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Soulja53 6F 75 6C 6A 61 Commented:
Is the vlan 905 interface on the 3560 switch? If so, just apply

Ip access-list extended internet
Deny tcp any any eq 80
Permit ip any any

Interface vlan 905
Ip access-group internet in
0
RailroadAuthor Commented:
Yes there is a vlan 905 interface on the 3560.

This doesn't block all internet traffic, only that on port 80.  It also blocks access to internal websites.  Also realized there is one computer on that VLAN that I need to allow internet access.  I've setup a reservation in DHCP to assign it to 172.20.5.50.

I tried this:

ip access-list extended No_Internet_VLAN905
 permit ip any host 172.20.5.50
 deny   ip host 172.20.0.1 any
 permit ip any any

ip access-group No_Internet_VLAN905 in

However this still didn't block access.  I also tried:

ip access-list extended No_Internet_VLAN905
 permit ip 172.20.0.0 0.0.255.255 any
 permit ip any host 172.20.5.50

This didn't work either.  Ideas?
0
Soulja53 6F 75 6C 6A 61 Commented:
Okay, so you want to allow access to internal networks and internet for all internet for that one host?

ip access-list extended No_Internet_VLAN905
permit ip any x.x.x.x 255.x.x.x  (this line is for your internal networks. if more than one network you can add multiple lines.)
permit ip host 172.20.5.50 any
deny ip any any

0
Check Out How Miercom Evaluates Wi-Fi Security!

It's not just about Wi-Fi connectivity anymore. A wireless security breach can cost your business large amounts of time, trouble, and expense. Plus, hear first-hand from Miercom on how WatchGuard's Wi-Fi security stacks up against the competition plus a LIVE demo!

RailroadAuthor Commented:
ip access-list extended No_Internet_VLAN905
 permit ip any host 172.20.5.50
 permit ip host 172.20.5.50 any
 deny   ip any host 10.30.2.1
 deny   ip host 10.30.2.1 any
 permit ip any 172.20.0.0 0.0.255.255
 permit ip 172.20.0.0 0.0.255.255 any

This doesn't work.  10.30.2.1 is the 3560's default gateway.  Ideas?
0
Soulja53 6F 75 6C 6A 61 Commented:
What you posted is not what I stated above:

ip access-list extended No_Internet_VLAN905
permit ip host 172.20.5.50 any
permit ip any 172.20.0.0 0.0.255.255
deny ip any host 10.30.2.1


interface vlan 905
ip access-group No_Internet_VLAN905 in


0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
RailroadAuthor Commented:
Ok so other than order and the fact that I have the "reverse" commands, mine is the same.  Why does yours work and not mine?
0
Soulja53 6F 75 6C 6A 61 Commented:
Did it work for you?
0
Soulja53 6F 75 6C 6A 61 Commented:
On another note: order is everything when it comes to ACL's.
0
RailroadAuthor Commented:
Yes, it's working.
0
Soulja53 6F 75 6C 6A 61 Commented:
Great!
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Switches / Hubs

From novice to tech pro — start learning today.