Block a foreign network with ACL

So my router has been present entered Syslog about ID escape tent.

How can I write an ACL that blocks ALL traffic destined for this network:

NetRange: 23.32.0.0 - 23.67.255.255
CIDR: 23.64.0.0/14, 23.32.0.0/11

I am new to ACL and still in school for Cisco. Bare with me. We do have much to covered ACL.

Thanks a ton!

Chris

This could be the ACL to only block these two networks and leave the rest. You probably want to google the term 'generic-mask' which is a mask the other way around:

ip access-list extended OUTSIDE-IN  deny ip 23.32.0.0 0.31.255.255 any  deny ip 23.64.0.0 0.3.255.255 any  permit ip any any
The ACL must be applied to the external interface in the inbound direction:
interface gig 0/0  description Your public interface  ip access-group OUTSIDE-IN in

Tags: Cisco Security

Similar Questions

  • All of a sudden, impossible to get on the network with PDA

    I have an office of cable to a WRT610Nv2 with 2 desktops on the network wireless.  I used to be able to jump on and off with my PDA and Netbook... now I can't.  PDA reports a 'Yin-Yang' symbol and the symbol of encryption at the network location... I think I somehow locked me out... help please

    Chuck

    Forgot to mention, basic wired computer and two desktops wireless are still working fine.

    Thanks for your reply, but turn the appliance market has not solved the problem... to dig around, I finally found that MAC addresses on my laptop had inadvertently been filtered by software... it sure was not easy to use.  I don't know how it happened all of a sudden, but when I "allowed" those blocked from MAC, everything was fine and I was able to get on the network with my PDA.

    Kind regards

    Chuck, CABGx3 + AAA

  • set up a home network with the PC using xp vista and windows 7

    I need to know how confugure my desktop vista and xp desktop and cell phone with my computer laptop windows 7.  detailed with inustrictions or links please.

    Hello

    You plug the computer via the network to a router or a switch card, and configuring their file sharing.

    ---------------------

    Win7 when configured on the peer-to-peer network has three types of configurations of sharing.

    Group residential network = only works between Win 7 computers. This type of configuration, it is very easy to entry level users to start sharing network.

    Working network = fundamentally similar to previous methods of sharing that allow you to control what, how and to whom the records would be shared with.

    Public share
    = network Public (as Internet Café) in order to reduce security risks.

    For the best newspaper of the results of each computer screen system and together all computers on a network of the same name, while each computer has its own unique name.

    http://www.ezlan.NET/Win7/net_name.jpg

    Make sure that the software firewall on each computer allows free local traffic. If you use 3rd party Firewall on, Vista/XP Firewall Native should be disabled, and the active firewall has adjusted to your network numbers IP on what is sometimes called the Zone of confidence (see part 3 firewall instructions

    General example, http://www.ezlan.net/faq#trusted
    Please note that some 3rd party software firewall continue to block the same aspects it traffic Local, they are turned Off (disabled). If possible, configure the firewall correctly or completely uninstall to allow a clean flow of local network traffic. If the 3rd party software is uninstalled, or disables, make sure Windows native firewall is active .

    ------------------------------

    If your network consists only of Win 7 and you want a simple network, use it.

    http://Windows.Microsoft.com/en-us/Windows7/help/videos/sharing-files-with-HomeGroup

    After you have configured the homegroup, scroll to the bottom for the Permission/security section.

    -----------------------------

    Win 7 networking with other version of Windows as a work network.

    In the center of the network, by clicking on the type of network opens the window to the right.

    Choose your network type. Note the check box at the bottom and check/uncheck depending on your needs.

    http://www.ezlan.NET/Win7/net_type.jpg

    Win 7 - http://windows.microsoft.com/en-us/windows7/Networking-home-computers-running-different-versions-of-Windows

    Win 7 network sharing folder specific work - http://www.onecomputerguy.com/windows7/windows7_sharing.htm

    Vista file and printer sharing - http://technet.microsoft.com/en-us/library/bb727037.aspx

    Windows XP file sharing - http://support.microsoft.com/default.aspx?scid=kb;en-us;304040
    Sharing printer XP - http://www.microsoft.com/windowsxp/using/networking/expert/honeycutt_july2.mspx

    Setting Windows native firewall for sharing XP - http://support.microsoft.com/kb/875357
    Windows XP Patch for sharing with Vista (no need for XP - SP3) - http://support.microsoft.com/kb/922120

    When you have finished the configuration of the system, it is recommended to restart everything the router and all computers involved.

    -------------

    If you have authorization and security problems, check the following settings.

    Point to a folder that wants to share do right click and choose Properties.

    In the properties

    Click on the Security tab shown in the bellows of the photo on the right) and verify that users and their permissions (see photo below Centre and left) are configured correctly. Then do the same for the authorization tab.

    This screen shot is to Win 7, Vista menus are similar.

    http://www.ezlan.NET/Win7/permission-security.jpg

    The Security Panel and the authorization Panel, you need to highlight each user/group and consider that the authorization controls are verified correctly.

    When everything is OK, restart the network (router and computer).

    * Note . The groups and users listed in the screen-shoot are just an example. Your list will focus on how your system is configured.

    * Note . There must be specific users. All means all users who already have an account now as users. This does not mean everyone who feel they would like to connect.

    ---------------------

    * Note. Some of the processes described above are made sake not for Windows, but to compensate for different routers and how their firmware works and stores information about computers that are networked.

    Jack-MVP Windows Networking. WWW.EZLAN.NET

  • Unable to connect to a wireless network with Windows 7 computer laptop.

    After resetting my router netgear wireless home network, I have not been able to access my own network with my laptop. I already had access to the internet with a wireless ethernet cable and ankles bound to the router. After reset the netgear router, I was able to access the internet from two other laptops XP and an Acer mini wireless with no problems at all. But my new laptop Toshiba with Windows 7 could not connect, even if he could detect the network. I tried all day even resort to the ethernet socket and wireless cable, but even that would no longer work. I was able to connect using this same cable attached.

    Hello

    Seems that the Wireless does not work on the Dell.

    This is the process to try to find what wrong with it.

    ------------------

    Assuming that wireless router is configured correctly, it is a signal and the wireless card on the computer is physically in.

    Maybe this can help.

    These steps and tell us where is the breaking point.

    Check the Device Manager for the wireless card valid entry.

    http://www.ezlan.NET/Win7/net_dm.jpg

    If there is no valid entry, remove any entry from fake and re - install the drivers for the wireless card.

    Check network connections to make sure that you have a network icon/entry wireless connection, and that the properties of the icon (right-click on the icon) are correctly configured with the TCP/IPv4 protocol in the properties of network connections.

    http://www.ezlan.NET/Win7/net_connection_tcp.jpg

    ------------------

    The wireless card drivers much also install utility wireless of the seller.

    To ensure that if there is Wireless Utility a seller is not running with the native Windows wireless utility (Service WLAN).

    ----------------

    Make sure you firewall No. preventing / blocks wireless components to join the network.

    Some 3rd AV/Firewall/security software part, s costume keep blocking aspects of Local traffic even it they are off (disabled).

    If possible set up the firewall correctly, /Security costume otherwise totally uninstall and get rid of its remaining processes that permit the own local network traffic flow.

    If the 3rd party software is uninstalled, or disables, make sure Windows native firewall is active .

    party like Hello and NetMagic 3rd network managers can block local traffic too.

    ---------------------------

    Stack TCP/IP work should look like.

    Right-click on the wireless network connection card, select status, details and see if she got an IP address and the rest of the settings.

    http://www.ezlan.NET/Win7/status-NIC.jpg

    Description is the data of the card making.

    The physical address is MAC of the card number.

    The xx must be a number between 0 and 255 (all xx even number).

    YY should be between 0 and 255

    ZZ should be between 0 and 255 (zz all the same number.)

    The date of the lease must be valid at the present time.

    * Note 1. IP that starts with 169.xxx.xxx.xxx isn't valid functional IP.

    * Note 2. There could be an IPv6 entries too. However, they are not functional for Internet or LAN traffic. They are necessary for Win 7 homegroup special configuration.

    ---------------------------------------------------

    A message in the small window that says connected wireless doesn't means that you are really a valid functional connection.

    Above everything is OK, you must be able to connect to the router.

    Connection to the router means that you can enter the IP of the router base in an address bar in one go, being able to connect and configure the router menus see.

    If it doesn't connect to the router, journal newspaper from any computer that can connect to the router wirelessly with a wire, disable wireless security, make sure that the wireless SSID broadcast is enabled and try to connect with no. wireless security.

    Enable security wireless after you eat to make a functional connection.

    Jack-MVP Windows Networking. WWW.EZLAN.NET

  • Extend my extreme network with another extreme - waiting for internet access

    Hello - I have a new generation Airport Extreme (let's call it Extreme1) connected to a Comcast modem and it works very well. The extreme will be the router that the modem has no router function. I'm trying to expand my network to another room with another extreme (let's call it Extreme2). I have a connection cable between two rooms. Extreme1 has an ethernet cable from one of its LAN ports connected on port WAN Extreme2. When I try to create a new network with Extreme2 (in aid of the same name, passwords, etc.) it does not work. He was suspended at the end when he is looking for a connection ("Waiting for internet access")-I did the following things based on what I read here:

    1. Changed IPv6 link local parameters
    2. Tried the whole upward on my Macbook and tried on my iphone
    3. The Wan first and then tried to change the configuration after you done for Extreme2 by creating a network
    4. Tried to create a network with Extreme2 connected directly to the modem
    5. Extreme2 factory reset after every attepmt

    And nothing works. Kicker is, I also have a reasonably new airport express and the same thing happens to her as well.

    Do I need to adjust some parameters of network that I'm not aware of? Is it possible that my LAN ports are disabled on Extreme2? It is brand new.

    Thanks for any help.

    Have you used the Apple Setup Assistant?  If you did, it had notified you that the extreme second was being configured "add using Ethernet. The wizard will automatically configure the second airport with the appropriate settings for you.  All you have to do is enter a name of device for the second AirPort Extreme.

    Here I'm assuming that you reset the second extreme to parameters by default until you set it up again and that your second Extreme is the current version of the "tower" or that of previous versions "flat or square.

    The example below shows an AirPort Express as the device which is the extension of the network, but you will see the name of your network and AirPort Extreme on your configuration screen.

    Post back if you need some tips on using the "Wizard" for your configuration.

  • Network with A60-155

    Having recently acquired this laptop, I tried to transfer files between it and my desktop (os w2k pro sp4) which is already networked with 2 other computers (ME and 98) in the House. Seems the laptop refuses to cooperate.
    I can ping 127.0.0.1, no problem, I can even ping IP of my desktop computer, but the laptop will not ping itself. The same office it detects my home network, but cannot access it. I have a light green and orange when ping of the desktop computer. I installed the latest drivers realtek for local networks (device drivers everything apparently works well)
    With the Office when this is the case I could uninstall the internet protocol (TCP/IP) and put things back by reinstalling, in XP this option is grayed out.

    Any suggestion would be appreciated as I am running out of ideas?

    See you soon

    Eddie

    Hi Eddie

    I guess you have a lot of experience with computer networks, and as you can see this sometimes a strange and inexplicable things.

    I'm sure that all the settings are good, but you can also try to connect your laptop directly to the desktop (peer to peer). On this way, you can check if it is possible to establish the connection.

  • set up a wireless network with 2 iMacs

    How to set up a wireless network with 2 iMacs?

    Need more information. Writing an effective communities of Apple Support question.

  • Compaq presario c700-c795tu: unable to connect to the WiFi network with WPA2 encryption

    Hi team,

    I tried all the options in your post and I am still unable to connect to WiFi with WPA2-PSK encryption.

    I am currently using the adapter network driver atheros 5007 wireless.

    Some of the links in your message that resolved this issue earlier are currently unavailable.

    It would be great if you could help me to solve this issue.

    Concerning

    Roger

    Here is the patch for WPA2 for XP SP2...

    Install and reboot and then see if you're OK...

    http://www.Microsoft.com/en-US/Download/details.aspx?ID=1974

    That's the only reason why I can think that now prevents you from being able to connect on a network with WPA2 Personal Security.

  • Blocking of blue screen with the analog voltage (WinXP, PCI-6251)

    Hello

    I'm looking to solve a problem of blue screen with my measure blocking
    application, which I am developing with C++. Blocking seems manifest
    a little random after a variable amount (500-50 000) of voltage analog
    measures. My application needs to make a huge amount of these digitally
    trigger voltage measures after a certain period of time, and I'm using a
    unique
    task to do. The task is stopped and started after a single measure
    is
    which is done around 10 000 - 100 000 times per second. For this
    because I do synchronized with the PCI-6251 map data acquisition and
    one
    Ztec oscilloscope card. It seems that the probability of blocking could be
    associated with
    the frequency of measurements of voltage that I perform.

    The
    the app itself is multithreaded, but I'm blocking concurrent access
    TO
    the card with lock - all access to the card are behind a single mutex

    lock, so simultaneous access is blocked. In any case, all data acquisition
    access
    o the map is initially a single thread, which is dedicated to the acquisition of data
    operations.

    I also did stress tests with Ztec scope map, which does not
    result
    in all the problems. I also disabled in order of acquisition of Ztec map data
    TO
    Make sure that it wasn't the card scope, the origin of the problems - the problem
    persistent, so this seems to point towards the direction of the nidaq map.

    The deadlock appeared when I used the original supplied with drivers
    the
    card. I installed the latest drivers (removed the device from)
    ' Windows
    Device Manager and your application Measurement & Automation, reinstalled), but the blue screen still appears.

    Blue screen gives me a few debug data, but it does not mention any

    files .dll or something that would be of course point to a specific file (driver). I enclose at least partially matching code snippets.

    Hello again! I've been in contact with a local support person, who suggested that I have use DAQmx_Val_FiniteSamps instead of DAQmx_Val_HWTimedSinglePoint. I don't have any other changes, but this (see below) and the problem disappeared, so this seems to be an acceptable solution, because I don't see at all why not do this way. (Thanks Henry!)

    DAQmxErrChk (DAQmxCfgSampClkTiming (task_reader, NULL, 100000.0, DAQmx_Val_Rising, DAQmx_Val_HWTimedSinglePoint, 1));
    DAQmxErrChk (DAQmxCfgSampClkTiming (task_reader, NULL, 100000.0, DAQmx_Val_Rising, DAQmx_Val_FiniteSamps, 2));

  • Message appear conflict of IP address at startup. Another computer already uses the network with the same IP address. How do I cure this?

    When my kids play online on the X - Box I get an error message on my laptop when I start after them. It is said there is an IP address conflict and that another device is already on the network with the same IP address. It does not affect me access internet even if. How can I fix thi.

    Hello

    1. which is the version of Windows installed on the computer? For example, Windows 7, Vista

    2. only the error message appears only when the Xbox is connected to the computer or at both times?

    3. have you made any software or changes to the material on the computer before this problem?

    Please answer these questions and provide additional information so that we can better guide you.

  • Migrated domain users are needed to access shared folders on the network with AD username old or need to share with the new AD ID

    Dear Sir

    Migrated domain users are needed to access shared folders on the network with AD username old or need to share with the new AD ID

    I am in a field & I'll migrate with a domain name.
    EX: now I'm in the field of the AAA tomorrow my domain name will change to BBB. User accounts are created in two AAA & BBB and the two domain user IDs are different.
    data servers are also migrating with the new domain.
    is it possible to access share with the old user id folder in new field or both to share the files again with the new user ID Active directory.
    Kind regards
    Chauvet J.

    Hello

    The question you have posted is related to professional level support. Please visit the below mentioned link to find a community that will support what ask you:

    http://social.technet.Microsoft.com/forums/en/category/WindowsServer/

  • several devices on the network with the same name

    I want to install Windows 7 OS computers on a domain with Small Business SERVER 2003.  Curiously, I see all the computers on the network, where I should be able to, but one of them WK02011, is not accessible from all Windows 7 systems because there are multiple devices with the same name on the network according to a diagnosticn check.  WK02011 is visible and accessible from other systems on the network that are runjning XP OS.  There is only one device named WK02011 on the network.  I don't have this problem with any other XP system - that is - I can see and access all of the other XP machines on the network with the exception of WK02011.  I can't access WK2011 from the server and the server indicates that it is multiple devices with the same ID.  Rename the XP would be complicated because of having to re - set up the service to the customer and then turn around and install 7 OS in the workstation in the coming days.

    How to find the ghost device double?

    Hello

    Your question is more complex than what is generally answered in the Microsoft Answers forums. It is better suited for Windows 7 on TechNet. Please post your question in the Technet forums. You can follow the link to your question:

  • Creation of network with accounts

    I want to create a network with computers running Windows operating systems. I have a wiorkgroup. Is it possible to do where I can create user accounts that can be connected through all the computers on the network? In my school, they have where they can disable any account at any time. They have something like shared files, but there are all these files that are not saved on the directory of files shared from any computer.

    Hello

    Yes, in general a network like what you describe requires a server.

    I would say that sticking with the Working Group is your best option to connect two computers to a home network, or more. With a shared folder or two, you should be able to do all the work in network, you will need.

  • I have 3 PC home networking with a router. How to connect my new hp 6500 has more so any pc can print

    I have 3 PCs at home with one with XP 32 bit and cable to connect to a router Internet, the secoond PC with windows 7 64 bit and wireless to the same router and the third PC with XP 64-bit with the same wireless router. Currently, two have their own wired to their own printers. I want to replace the two existing printers with my newly purchased HP Officejet 6500 has more which will be located next to the XP 32 bit PC which has currently a cable connected to the router. How can I connect the new HP Officejet 6500 has more to my network to allow any of the three computers to print to the officejet and install the HP software on all 3 PC and if so what progs? I'm sorry if it's a very basic question, but I'm not a computer scientist and the help delivered with the printer documentation does not appear to this lay person to give this information on how to set up a home network with this printer. Thanks in advance for any advice.

    Mike4D

    Hello

    You can choose one of the following 2 options:

    Option 1: simila in the image above

    Connect the printer to the router,

    Connect a PC to the router (not wireless computer)

    Option 2:

    Connect a PC to the router (not wireless computer)

    Connect the printer to the wireless router

    Option 1 makes the computer without a connection to the printer. For the other two computer is the same on the two configuration options.

    Please use the following book to configure things

    http://h10032.www1.HP.com/CTG/manual/c00389927.PDF

    Kind regards.

  • my windows says that another computer is running in the same network with the same ip address, please contact

    Today morning when I opened my samsung mini, it displays a message that another computer is running on the same network with the same ip address please find a solution for this

    In most home networks where multiple devices are connected to a router, router will assign an IP address to each device (via DHCP). This method keeps usually different devices to get the same IP address, but if you restart your router, it will not address remembered that he released before it was restarted.  This condition can also occur if you manually assigned an IP address to a device located in the router's DHCP range.  If the problem is not due to manually assign an IP address, then this condition will be corrected over time.  But if you're in a hurry, you can unplug your router from the wall and stop all computing devices on it.  Then plug the router back in and bring up all your devices again one by one.

    HTH,

    JW

Maybe you are looking for

  • my default text will come out as question marks in a box

    I am on OS x EL Capitan Office. My default text will come out as question marks in a box for each character?

  • merge with deployed FireFox favorite silently

    Hi allI am trying to create a deployment for FireFox on our network of company (always under XP).{There is the problem that I have, / a lot of people who already have a manually installed installed FF version and I need to create a deployment that "t

  • Some Brazilian certificates are not accepted by Firefox

    Some certificates from the Brazilian Government sites are not accepted by Firefox

  • OfficeJet 7500 7500: a a Driver Confusion

    I can not all the functions of my Officejet 7500 has hade work. If I install the drivers from the disc that came with the printer, the printer works but the scanner app is not installed. If I download the newest driver on the website of H - p, the sc

  • service pack 2 problems

    I installed SP2 successfully, but after installing im now stuck to my login screen.  This never happened b4 until I installed this update.  whenever I tried to connect to my computer, it sends me to the login screen.  the only way I can get to my off