Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Access-list deny ip

Status
Not open for further replies.

WaltK

Technical User
Aug 5, 2001
10
US
I have tried unsuccessfully to add an access-list which denies ip for a group of people. Technically our network is 10.1.0.0 255.255.0.0, although all our hosts are using 10.1.1.0 only. I thought that if I put all individuals who I want to block access on 10.1.5.0, I should be able use to use access lists.

I have tried several variations of the following standard access list, but extended lists don't seem to work either.

access-list 5 deny 10.1.5.0 0.0.0.255
access-list 5 permit 10.1.1.0 0.0.0.255

Applying this list to the outbound serial interface. I have changed the order and played with the wildcard bits, but nothing seems to work. I have replaced the permit 10.1.1.0 with permit any, and this opened everything up.

Any help would be appreciated. Thanks.
 
If the "permit any" worked that means that the topology of the network and the way you assigned IP addresses do not match properly. Try using extended IP lists to block access for a host at a time and leave all the other open. This way you can diagnose easier what is going on. Also did you use a router to divide the two networks? Try to explain how is the network layed out so I can help you pinpoint the problem.
 
There is only 1 network, but I was hoping that I would still be able to block certain host ID's. I did try blocking my own address as a test, using the following

access-list 5 deny 10.1.1.50
access-list 5 permit any

and applying this to the oubound serial interface, but I was not prevented from going through the router.

Thanks for looking into it.

 
When you apply the access list to the outbound port, what is the exact command you use?
 
Hi ,

Access List are very logic . Still I am not able to understand your network . However , below are some very important highlights you should consider :

01. whom you want to permit ( since there is a default deny to the end of the access list any way .. so just think about whom you want to permit not whom you want to deny )

02. You should have a very clear picture of inbound and outbound . they make a huge diffrence .

Good Luck .
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top