Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations TouchToneTommy on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

How to Implement this Access-list

Status
Not open for further replies.

kmcelroy

ISP
Jan 22, 2002
15
US
I have a 3662 router with the following:

Serial 0/1 Connection to Internet
F0/0 Connection to Switch for LAN Use

My company wants to block the use of MSN Messenger to certain workstations. So I set the following up and it doesn't work:

access-list 103 deny tcp host 192.168.0.101 any eq 1863 access-list 103 permit ip any any

applied it to F0/0 as ip access-group 103 out

Can any help me with this one?
 
isn't the IP address going to get NAT'd prior to leaving via that interface? Perhaps you should apply that list to the "inside" interface?
 
The IP is just made up, I am using a public address that requires not to be translated
 
MSN Messenger will use TCP port 80 if it can't use it's regular port. The only way to block MSN messenger is to get a hold of the messenger server's IP addresses and block them that way.
 
thanks baddos, good to know.
If it's any help, I believe MSN Messenger servers are on the 64.4.0.0/18 network...
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top