Solved

ACL on Cisco 3560

Posted on 2013-06-12
1
416 Views
Last Modified: 2013-07-15
Hello Experts,

I have ACL's on a few internal VLAN's and folks are beginning to require the use of Webex. The website says this:

WebEx services are offered over the following IP ranges:

66.163.32.0 - 66.163.63.255
209.197.192.0 - 209.197.223.255
173.243.12.0 - 173.243.12.255 (Subnet)

http://www.webex.com/webexconnect/orgadmin/help/index.htm?toc.htm?17161.htm

Can I use an IP-range command or do I need to list each of these networks individually?

Or for example, just opening a full class B? Would you recommend against this? I can still be more granular on the edge firewall as the ACL's are more flexible. (Also I know the website says it is generally not recommended but it seems they don't change IP's very often.)

66.163.x.x
209.197.x.x

Also, do I specify the command with the mask or the wild card? For example 255.255.0.0 or 0.0.255.255?

Thanks Experts!
0
Comment
Question by:zequestioner
1 Comment
 
LVL 45

Accepted Solution

by:
Craig Beck earned 500 total points
ID: 39243804
ACLs use wildcards, so 0.0.0.255 format.

You shouldn't just specify a whole /16 - that would defeat the object of the ACL, unless you're wanting to allow access to Apple (they have their own /8).

Your ACL should look something like this...

ip access-list extended WebEx
 permit ip any 66.163.32.0 0.0.31.255
 permit ip any 209.197.192.0 0.0.31.255
 permit ip any 173.243.12.0 0.0.0.255
0

Featured Post

How to improve team productivity

Quip adds documents, spreadsheets, and tasklists to your Slack experience
- Elevate ideas to Quip docs
- Share Quip docs in Slack
- Get notified of changes to your docs
- Available on iOS/Android/Desktop/Web
- Online/Offline

Join & Write a Comment

Problem Description:   Couple of months ago we upgraded the ADSL line at our branch office from Home to Business line. The purpose of transforming the service to have static public IP’s. We were in need for public IP’s to publish our web resour…
Shadow IT is coming out of the shadows as more businesses are choosing cloud-based applications. It is now a multi-cloud world for most organizations. Simultaneously, most businesses have yet to consolidate with one cloud provider or define an offic…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

743 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now