1st question:
I need to filter out 3 range of IP. Can anybody help with the ACL mask?
65.90.5.1 - 65.90.5.200 (Permit HTTP access)
65.90.5.100 - 65.90.5.200 (Permit FTP access)
65.90.5.201 - 65.90.5.255 (Permit UDP PORT 22 access)
2sd question:
Below is my access list: I aaply it to serial1 interface T1. Everything seem working axcept PC within my network 65.90.5.0 not able to resolve DNS? Did anybody how to correct my mistake?
Extended IP access list 101
deny ip 65.90.5.0 0.0.0.255 any
permit tcp any any established
deny ip 127.0.0.0 0.255.255.255 any
deny ip 10.0.0.0 0.255.255.255 any
deny ip 172.16.0.0 0.15.255.255 any
deny ip 192.168.0.0 0.0.255.255 any
deny ip any 0.0.0.255 255.255.255.0
deny ip any 0.0.0.0 255.255.255.0
deny ip 255.0.0.0 0.255.255.255 any
deny ip 224.0.0.0 7.255.255.255 any
permit tcp any 65.90.5.0 0.0.0.255 eq www
permit tcp any 65.90.5.0 0.0.0.255 eq 443
permit udp any 65.90.5.0 0.0.0.255 eq 80
permit udp any 65.90.5.0 0.0.0.255 eq 443
permit tcp any host 65.90.5.55 eq smtp
permit tcp any host 65.90.5.5 eq smtp
permit tcp any host 216.140.16.254 eq domain
permit udp any host 216.140.16.254 eq domain
permit tcp any host 216.140.17.254 eq domain
permit udp any host 216.140.17.254 eq domain
permit tcp any host 65.90.5.2 eq domain
permit udp any host 65.90.5.2 eq domain
permit tcp any host 65.90.5.3 eq domain
permit udp any host 65.90.5.3 eq domain
permit tcp any host 65.90.5.4 eq domain
permit udp any host 65.90.5.4 eq domain
permit tcp any host 65.90.5.5 eq domain
permit udp any host 65.90.5.5 eq domain
permit tcp any 65.90.5.0 0.0.0.100 eq ftp-data
permit tcp any 65.90.5.0 0.0.0.100 eq ftp
deny tcp host 216.142.73.246 host 216.142.73.246
deny tcp host 65.90.5.1 host 65.90.5.1
permit icmp any any
permit udp any 65.90.5.0 0.0.0.255 eq 22
permit tcp any host 65.90.5.55 eq 110
permit tcp any host 65.90.5.5 eq 110
deny ip any any log
Extended IP access list 102
permit ip 65.90.5.0 0.0.0.255 any
deny ip any any
I added the following lines to the buttom of Access-list 101, and my network 65.90.5.0 can resolve DNS. Are this lines secure?
permit tcp any any eq domain
permit udp any any eq domain
permit udp any any range 1024 5999 (39 matches)
I need to filter out 3 range of IP. Can anybody help with the ACL mask?
65.90.5.1 - 65.90.5.200 (Permit HTTP access)
65.90.5.100 - 65.90.5.200 (Permit FTP access)
65.90.5.201 - 65.90.5.255 (Permit UDP PORT 22 access)
2sd question:
Below is my access list: I aaply it to serial1 interface T1. Everything seem working axcept PC within my network 65.90.5.0 not able to resolve DNS? Did anybody how to correct my mistake?
Extended IP access list 101
deny ip 65.90.5.0 0.0.0.255 any
permit tcp any any established
deny ip 127.0.0.0 0.255.255.255 any
deny ip 10.0.0.0 0.255.255.255 any
deny ip 172.16.0.0 0.15.255.255 any
deny ip 192.168.0.0 0.0.255.255 any
deny ip any 0.0.0.255 255.255.255.0
deny ip any 0.0.0.0 255.255.255.0
deny ip 255.0.0.0 0.255.255.255 any
deny ip 224.0.0.0 7.255.255.255 any
permit tcp any 65.90.5.0 0.0.0.255 eq www
permit tcp any 65.90.5.0 0.0.0.255 eq 443
permit udp any 65.90.5.0 0.0.0.255 eq 80
permit udp any 65.90.5.0 0.0.0.255 eq 443
permit tcp any host 65.90.5.55 eq smtp
permit tcp any host 65.90.5.5 eq smtp
permit tcp any host 216.140.16.254 eq domain
permit udp any host 216.140.16.254 eq domain
permit tcp any host 216.140.17.254 eq domain
permit udp any host 216.140.17.254 eq domain
permit tcp any host 65.90.5.2 eq domain
permit udp any host 65.90.5.2 eq domain
permit tcp any host 65.90.5.3 eq domain
permit udp any host 65.90.5.3 eq domain
permit tcp any host 65.90.5.4 eq domain
permit udp any host 65.90.5.4 eq domain
permit tcp any host 65.90.5.5 eq domain
permit udp any host 65.90.5.5 eq domain
permit tcp any 65.90.5.0 0.0.0.100 eq ftp-data
permit tcp any 65.90.5.0 0.0.0.100 eq ftp
deny tcp host 216.142.73.246 host 216.142.73.246
deny tcp host 65.90.5.1 host 65.90.5.1
permit icmp any any
permit udp any 65.90.5.0 0.0.0.255 eq 22
permit tcp any host 65.90.5.55 eq 110
permit tcp any host 65.90.5.5 eq 110
deny ip any any log
Extended IP access list 102
permit ip 65.90.5.0 0.0.0.255 any
deny ip any any
I added the following lines to the buttom of Access-list 101, and my network 65.90.5.0 can resolve DNS. Are this lines secure?
permit tcp any any eq domain
permit udp any any eq domain
permit udp any any range 1024 5999 (39 matches)