Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Access List

Status
Not open for further replies.

Icekola

Technical User
Aug 26, 2007
11
US
I want to deny any IP WAN traffic from accessing my LAN unless the traffic was originated from the LAN.

How would I accomplished this. I don't think this can be done via a standard nor extended ACL. I think I need a reflexive ACL but I'm not familiar with those just yet.

Cisco 2621
FA0/0 = LAN
FA0/1 = WAN

Your help is appreciated, thanks.


 
look at implementing CBAC and uRPF

I hate all Uppercase... I don't want my groups to seem angry at me all the time! =)
- ColdFlame (vbscript forum)
 
Resolved it with the following. May not be the most efficient way but it works :p

------------------------------------------------------------------
NAT:

ip nat inside source list 1 interface FastEthernet0/1 overload

access-list 1 remark NATADDY
access-list 1 permit 192.168.1.0 0.0.0.255

interface FastEthernet0/1
ip nat outside
------------------------------------------------------------------
Reflexive ACL to allow DHCP and remote access from work but denies all WAN traffic unless originated from LAN:

ip access-list extended INBOUND
permit udp any eq bootps any eq bootpc log
permit ip host x.x.x.x any log
evaluate MIRROR

ip access-list extended OUTBOUND
permit ip any any log reflect MIRROR

interface FastEthernet0/1
ip access-group INBOUND in
ip access-group OUTBOUND out
 
Back in the day, a poor man's version of CBAC would be the "established" keyword at the end of a permit line for TCP traffic inbound from WAN. That, of course, is easily bypassed.

CCNP, CCDP, CCIP
Core Network Planner, ISP
 
Not unless you do "eq ack, eq sin, eq fin, etc.

/ word

10 ? "TIMMAY!!!"
20 goto 10
run
TIMMAY!!!
TIMMAY!!!
TIMMAY!!!
TIMMAY!!!
TIMMAY!!!
TIMMAY!!!
TIMMAY!!!
TIMMAY!!!
TIMMAY!!!
TIMMAY!!!
TIMMAY!!!
TIMMAY!!!
TIMMAY!!!
TIMMAY!!!
TIMMAY!!!
TIMMAY!!!
TIMMAY!!!
TIMMAY!!!
TIMMAY!!!
TIMMAY!!!
TIMMAY!!!
TIMMAY!!!
TIMMAY!!!
TIMMAY!!!
TIMMAY!!!
TIMMAY!!!
TIMMAY!!!
TIMMAY!!!
TIMMAY!
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top