Hot Downloads

Welcome, Guest
Username: Password: Remember me

TOPIC: ACL

ACL 8 years 7 months ago #25623

Hi,
I have been asked to create a acl for the following problem

There is a Router directly connected two networks (student and staff)
i have just put in two pcs to represent this
the student network is
202.1.1.0

the staff network is
202.1.2.0

My task is to create an acl that does the following
(a) allows staff to access the student network
(b) disallows all access from the student to staff
(c) but allows tcp (ack, etc etc)

so the router in middle student on left (interface fa0/0) and staff on right (interface fa0/1)

my acl is:
access-list 101 permit tcp 202.1.2.0 0.0.0.255 202.1.1.0 0.0.0.255 established

access-list 101 deny tcp 202.1.1.0 0.0.0.255 202.1.2.0 0.0.0.255 established

then went into fa0/0
ip access-group 101 in
then went into fa0/1
ip access-group out

but it fails when i ping wat is wrong?
The administrator has disabled public write access.

Re: ACL 8 years 7 months ago #25624

  • Chojin
  • Chojin's Avatar
  • Offline
  • Senior Member
  • Posts: 251
  • Karma: 0
ping is ICMP, not TCP.

Try again with ICMP instead of TCP
CCNA / CCNP / CCNA - Security / CCIP / Prince2 / Checkpoint CCSA
The administrator has disabled public write access.

Re: ACL 8 years 7 months ago #25666

But remb in a real life situation you will need use acknowledgments and other tcp stuff, i don't want to block all access same important process still need to take place
The administrator has disabled public write access.
Time to create page: 0.075 seconds

CCENT/CCNA

Cisco Routers

  • SSL WebVPN
  • Securing Routers
  • Policy Based Routing
  • Router on-a-Stick

VPN Security

  • Understand DMVPN
  • GRE/IPSec Configuration
  • Site-to-Site IPSec VPN
  • IPSec Modes

Cisco Help

  • VPN Client Windows 8
  • VPN Client Windows 7
  • CCP Display Problem
  • Cisco Support App.

Windows 2012

  • New Features
  • Licensing
  • Hyper-V / VDI
  • Install Hyper-V

Linux

  • File Permissions
  • Webmin
  • Groups - Users
  • Samba Setup