Solved

ACL on Cisco 3560

Posted on 2013-06-12
1
428 Views
Last Modified: 2013-07-15
Hello Experts,

I have ACL's on a few internal VLAN's and folks are beginning to require the use of Webex. The website says this:

WebEx services are offered over the following IP ranges:

66.163.32.0 - 66.163.63.255
209.197.192.0 - 209.197.223.255
173.243.12.0 - 173.243.12.255 (Subnet)

http://www.webex.com/webexconnect/orgadmin/help/index.htm?toc.htm?17161.htm

Can I use an IP-range command or do I need to list each of these networks individually?

Or for example, just opening a full class B? Would you recommend against this? I can still be more granular on the edge firewall as the ACL's are more flexible. (Also I know the website says it is generally not recommended but it seems they don't change IP's very often.)

66.163.x.x
209.197.x.x

Also, do I specify the command with the mask or the wild card? For example 255.255.0.0 or 0.0.255.255?

Thanks Experts!
0
Comment
Question by:zequestioner
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
1 Comment
 
LVL 46

Accepted Solution

by:
Craig Beck earned 500 total points
ID: 39243804
ACLs use wildcards, so 0.0.0.255 format.

You shouldn't just specify a whole /16 - that would defeat the object of the ACL, unless you're wanting to allow access to Apple (they have their own /8).

Your ACL should look something like this...

ip access-list extended WebEx
 permit ip any 66.163.32.0 0.0.31.255
 permit ip any 209.197.192.0 0.0.31.255
 permit ip any 173.243.12.0 0.0.0.255
0

Featured Post

Free NetCrunch network monitor licenses!

Only on Experts-Exchange: Sign-up for a free-trial and we'll send you your permanent license!

Here is what you get: 30 Nodes | Unlimited Sensors | No Time Restrictions | Absolutely FREE!

Act now. This offer ends July 14, 2017.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Exchange server is not supported in any cloud-hosted platform (other than Azure with Azure Premium Storage).
Concerto Cloud Services, a provider of fully managed private, public and hybrid cloud solutions, announced today it was named to the 20 Coolest Cloud Infrastructure Vendors Of The 2017 Cloud  (http://www.concertocloud.com/about/in-the-news/2017/02/0…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …
Suggested Courses

688 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question