ACL for only the port UDP Internet Permittin

Hello

I'm setting up a 3560 switch has 3 VLAN that is

VLAN 223 - Server - 10.4.223.0/24 - 10.4.223.1

VLAN 224 - user - 10.4.224.0/24 - 10.4.224.1

VLAN 225. -internet - 10.4.225.0/24 - 10.4.225.2

10.4.225.1 is the Gulf war to the ISP of the switch which I use as a jump on the switch.

VLAN 225 in which an Internet service provider is talk to internet, I want to only allow only udp to 10.4.223.2. IPS of rest should not go to the internet but vlan 224 and vlan 225 should access vlan 223.

I write access list, but it does not work

Subnet_Vlan223 extended IP access list

allow udp all 10.4.223.1 0.0.0.255 eq 53

refuse the host ip 10.4.225.1 10.4.224.3 0.0.0.252 - I want to 10.4.224.3 - 254 host must be prevented to communicate with 10.4.225.1

allow an ip

interface Vlan223

IP access-group Subnet_Vlan223 in

concerning

Sliman

The first IP address must be the source and the destination of the second. Since it is an inbound access list, your ACL look backward.

The deny statement may need to be written as two lines: permettre.2 to acces.1, refuse all the class C network to a.1

Tags: Cisco Security

Similar Questions

  • Why so slow and fat out put for only the clip size small 1 sec?

    Why so slow and fat out put for only the clip size small 1 sec?

    Hello

    I just apply simple ray tracing 3d in AE and then try to make it by media encoder

    Meia encoder says 4 hours so he could make

    my clip was 15 sec not hd (I do not change all of the settings in media encoder to make)

    then I cut it to 1 sec encoder media took 20 minutes to make

    out put

    4.12 MB

    .avi file

    1 sec

    Why what is happening

    This only happens when I apply ray trace 3d not for others

    Thank you

    As they say - "a picture is worth a thousand words" thus:

    This is a screenshot of the small video clip (full HD) with curvature layer with RayTracing (see render estimated times):

    And the same video clip with 3D classic (without RayTracing) and effect of Warp Mesh (rendering was so fast that he even showed no estimated time - but you can see the final rendering time):

    So you almost 1, 5 h with RayTracing vs 11 dry without.

  • 2015 Macbook: keyboard product strikes without touching (for only the T key)

    I have a Macbook or 2015 in perfect condition, original owner, never damaged, still under warranty. A few months ago, I noticed that the T key would occasionally insist on its own. With nothing, contacting the keyboard, keys T would have picked up.

    There has been sporadic for a few months, then a few weeks ago, it became much more common. I only use the computer because I disabled the T key using the carabiner and remapped Cmd + 5 so that it sends that t. typing is not easy, so maybe you can forgive me if my message is short?

    Has anyone experience this problem or have any recommendations? Thank you!

    Could be something as simple as small pieces of debris that may have gotten

    trapped under the key - and once there, could interfere with spring

    parts below. You could read through another debate where I made

    post links to some sources on how to clean the keyboard without taking

    Apartment. With... canned air that one is an Apple support article.

    There are also other links to the iFixit site where the keys of the keyboard are

    shows removed and the section of spring is as well. There were two answers

    to the original question of the user because the first expired while I did some research.

    Re: Enter issues -problems of keyboard macbook 12 inch retina

    Re: Enter key 2 issues -key-face and spring cleaning info button

    Details to some extent are covered, and there is also a link to consider a

    Appointment of genius Apple Store, if you want them to look over

    and they may be able to clean it up during your reserved time; or, if

    no official retail Apple Store is available, maybe (if you do not want to)

    an Apple authorized service provider may; a genius would be free of charge

    to watch over and examine it. Under AppleCare, likely repairs are covered.

    However this is equivalent...

    Good luck & happy computing!

  • Why is the port udp 137 used during a remote desktop session?

    I am currently seeing a lot of messages on my firewall indicating port 137 udp is blocked.  I think that when I use remote desktop to a remote system, which attempts to connect to me via the udp port 137 remote systems.  If this is true, why?  This is necessary or if I can change this behavior?

    Hello

    UDP 137 is used by NetBIOS in Windows 7 file sharing.

    According to what you are doing when you use Remote Desktop on your network, it can call the UDP137.

    If it does not interfere with something functional you need to do, leave him alone. The Job firewall is to block aspects of network traffic. You don't have to feel 'sorry' to him do his job.

    Jack-MVP Windows Networking. WWW.EZLAN.NET

  • How to hide welcome to and disconnection for only the specified pages link

    Hello

    I have a few pages in my application like forget password page, in which I won't show the disconnection on upper link and welcome message. For the rest of the other pages its ok. If I change the body of model to do then all pages the user welcome disappears, where I need to hide it for a specific page only.

    Please give an idea.

    Thank you

    Chandra Bhanu

    Access shared models/components.

    Find the page template you are using and click on copy.

    Go to the copy and search & USER. and #NAVIGATION_BAR # and delete.

    Go to each page that don't no need of user and navigation and assign the new model.

    This will get rid of the user details and the navigation bar.

    Gus

  • My site is not secure for only the users of firefox, how can I solve this problem?

    My site is not secure for customers who use firefox only, how can I solve this problem?
    wizardsofthewest.com

    Hello, apparently not all necessary intermediate certificates are installed on your server.

    http://www.Networking4all.com/en/support/tools/site+check/report/?FQDN=wizardsofthewest.com & Protocol = https

    http://www.sslshopper.com/SSL-checker.html#hostname=wizardsofthewest.com

    For more information please contact godaddy support...

  • How to set history for only the administrator of a computer at home?

    I want to give my tab history to not allow anyone other than me to remove the information. I'm the administrator of this computer at home and want to keep an eye on what my children and grandchildren are doing on that computer for their own safety. How can I do this?

    History-locking is not possible (and if it was there are lots of ways to work around). Parental control allows you to keep an eye on websites visited, block / unblock websites with parental control on Firefox

  • migration assistant for only the user folder

    I'm helping a student who left a Time Machine backup College but suffered a hard disk failure in his MacBook Pro here. We can't clone or make a backup hard drive TM or run the recovery partition. All we could do was to copy the user on an external hard drive folder.

    Apple replace the drive under warranty and installation of system software. When we reboot the machine that is repaired, we will be able to use setup assistant/migration assistant to transfer the folder to the user as it will not be recognized as another backup Mac or MC? Otherwise, what is the best way to get it on the laptop and recognized as a user it?

    (She needs to work on its data before returning to the University is not an option to wait until she is back with his backup TM)

    As far as I know the Migration can be done with just the folder of the user. What I would say is that you copy the text of the drive backed up by a folder. In other words, open the two folders of Documents and copy the text from the backup folder of Documents to the Documents from the computer folder. This, for everything except the library. Most of what is in the library will be restored as the computer is reconfigured and the applications are put back in place.

  • What is the best/best way to cut a folder of videos for only the useful parts?

    Hello

    I have a folder of 30 + videos that have many unstable parts for them. What is the best way to cut the unusable parts in transfer?

    Best

    Hi Gorazdr27768010,

    I have a folder of 30 + videos that have many unstable parts for them. What is the best way to cut the unusable parts in transfer?

    Use the media browser and import the required clips.

    Import media into Premiere Pro | Adobe first Pro CC tutorials

    And you can apply points in the source monitor and exit before adding them to the timeline.

    Score Points in the Source monitor output and first Pro CC - YouTube

    Answer please, if this is useful.

    Thank you

    Ilyes Singh

  • Optimize the PDF scanned for ONLY the PDF FILES in a folder?

    Using the Action Wizard to batch optimize scanned documents.  When you select a folder, how can we only to optimize PDF files and jump on the conversion of all other types of files (JPG, TIF, DOC) ?  Currently it is to convert all the files in the folder in PDF format, but we want only those who are already PDF. optimize

    Thank you!

    ATC

    Copy the PDF files into a new folder and run the action on this issue.

  • 2821 ACL for the range of IP addresses

    We use an old Cisco 2821 on the edge of the internet for the initial incoming traffic filtering.  To try to block some networks of suppliers that are a source of SPAM, we have tried to apply an ACL that included a range of addresses as follows:

    access-list 110 deny host ip 198.20.160.0 0.0.31.255 255.255.255.255

    This command has been shorted to what follows in the running configuration:

    access-list 110 deny host ip 198.20.160.0 all

    The ACL doesn't seem to work, as we have always received spam through on this range.

    Any help is greatly appreciated.

    Thank you for your time.

    Hello

    Your syntax ACL deny only the host 192.20.160.0.

    If you look below

    access-list 110 deny ip host 198.20.160.0 0.0.31.255 255.255.255.255

    You have the source specified as host (198.20.160.0 host)

    destination like any other host (network mask and subnet inalid - 0.0.31.255 255.255.255.255)

    You want to block what subnet or network, gave me a source and destination subnet? . Will be recorrect the ACL

    HTH

    Sandy

  • No sound on the Port Replicator port II (Tecra S11 - 12M)

    Hello! Because today, I have no sound on my sound from the Port Replicator II (PA3680E-1PRP) plug to run my external speakers. Instead, the internal speakers are running. On the laptop itself, making works well, only the port replicator appears to be dead.

    It has worked well over 10 months now without any complaint. I've seen a few similar cases in forums but no answer that could help me. I didn't lie all the drivers again.

    I work with WIN7/64-bit Service Pack 1.

    Anyone know how to fix?

    Thank you, christophe

    Hello

    Recommend to check this thread:
    http://forums.computers.Toshiba-Europe.com/forums/thread.jspa?threadID=56460

    * Milo_Tweenie wrote: *.

    + Did not know that the audio 3.5 mm output jack is actually run by a USB hub in the duplicator. +
    + Concluded that the multimedia USB Audio Device was not installed driver for the audio port. Click the button to update the driver, it has found the driver automatically and now I have sound. +

  • Something similar to groups of objects, but for the ports? (must be used on an ACL)

    Hello community!

    I'm fairly new, when it comes to firewalls, but I have some experience with routers and switches, so I'm not completely lost.

    Practically, we all know that a group object is a large bucket to throw things and then managing them as a single group, which is very useful for many reasons... so is there something similar that we can use in an ACL for the port?

    Say so, let that I want to allow the following ports:

    • 80
    • 443
    • 25
    • 30500
    • 20500
    • 8080
    • 14600
    • 21
    • 753
    • 22

    And instead of doing something like this:

    dmz_access_in list extended access permit tcp host WEB host EXT - WEB eq 80

    dmz_access_in list extended access permit tcp host WEB host EXT - WEB eq 443

    dmz_access_in list extended access permit tcp host WEB host EXT - WEB eq 25

    dmz_access_in list extended access permit tcp host WEB host EXT - WEB eq 30500

    dmz_access_in list extended access permit tcp host WEB host EXT - WEB eq 20500

    access-list extended dmz_access_in permit tcp host WEB host WEB-EXT eq 8080

    dmz_access_in list extended access permit tcp host WEB host EXT - WEB eq 14600

    dmz_access_in list extended access permit tcp host WEB host EXT - WEB eq 21

    dmz_access_in list extended access permit tcp host WEB host EXT - WEB eq 753

    dmz_access_in list extended access permit tcp host WEB host EXT - WEB eq 22

    do something like:

    dmz_access_in list extended access permit tcp host WEB host WEB-EXT eq PORT_LIST1

    Thank you!!

    PD: Excuse me if some port above are not TCP, if just one example. I just start typing all the numbers that came to my head.

    Hey Rolando,

    On a SAA, you can combine services and protocols based on the source/destination in an object-group service oriented. Your example would look like this:

     object-group service PORT_LIST1 service-object tcp destination range 21 22 service-object tcp destination eq 25 service-object tcp destination eq 80 service-object tcp destination eq 443 service-object tcp destination eq 753 service-object tcp destination eq 8080 service-object tcp-udp destination eq 14600 service-object tcp destination eq 20500 service-object tcp destination eq 30500

    You can create also integrate groups:

     object-group service WEB_PORTS service-object tcp destination eq 80 service-object tcp destination eq 443 object-group service PORT_LIST1 group-object WEB_PORTS service-object ...

    This type of group is going where the Protocol is specified in the ACL:

     access-list dmz_access_in extended permit object-group PORT_LIST1 object HOST object EXT-WEB

  • My start page for Firefox has no internet or great, address only the Google search box area.

    Before the last update of my Mozilla Firefox, the start page for Firefox contained one area internet address to the top of the screen, where I could enter a Web address and go success. She also showed the Google search box in the middle of the screen.

    Now, after the update of Firefox, the start page shows that the Google search box. There is no internet address box or an impressive "box", which, according to my reading of the new features, is supposed to have replaced the internet address box.

    • If, under Windows, Firefox 3.6 the menu bar is hidden, then press on and hold down the ALT key, or press F10, which should make the "menu bar" appear
    • Go in "view > toolbars" and tick "Menu bar" with a click on it to make them permanent. See what happened to the file, edit and view menus?).
    • Make sure you have the "Navigation toolbar" and the "Personal bar" visible: "view > toolbars".
    • Is he missing elements then see if you can find them in the window "view > toolbars > customize.
    • If you see the item in the window customize then bring her back in the window to customize one of the toolbars.
    • So, in "view > toolbars > customize", you do not see this item and then click the button "Restore Default Set.

    See http://kb.mozillazine.org/Toolbar_customization

  • Problems with static IP setting for the port forward through 2 routers

    I currently have cable internet connected to a router (Linksys E2000 w / v1.0.03 firmware). This router is connected to another router, a Linksys E3200 with firmware v1.0.02. In order to correctly forward ports through the E3200, I understand that I need to set up a static IP address on the router.

    I almost followed the steps in this video, but when I enter all the IP addresses for the static IP address settings, it allows me to access the router configuration page. I try to get the new IP address that I gave (which he tries to move automatically once I have save settings) and the connection times out. I am able to access internet otherwise, however. From here, I have to do a factory reset on the router and start from square one.

    Anyone have any ideas? I'm quite frustrated and would like to get ports forwarded so I can get my server properly set in place.

    1. If it has connected LAN - LAN you will need to disable the DHCP server on the E3200.

    2. the best option would be to use the 'bridge' on the E3200 mode (in the latest firmware) and connect the internet port to the main router.

    3. If connected LAN - LAN (or in Bridge mode) all internet related functions on the E3200, including ports are not relevant. There is no need to set up the port on the E3200 redirects. All shipping is done only on the E2000 and nowhere else.

    4. What is the address LAN IP of the E3200? What is the address LAN IP of the E2000?

Maybe you are looking for