Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Access list

Status
Not open for further replies.

windsorking

Technical User
Nov 15, 2000
6
US
I have PC's and a device called an instant internet box on the same segment. Can I set up an extended IP access list to prevent particular PC's from getting to the Internet box.

My confusion is in the fact that they are both on the same segment. I thought trafic would have to pass through the router in order to filter it.
 
You can place the Instant Box on it's own segment then apply the access list. You could use VLANs on a switch, if you have a fairly new switch you could use some QOS to the port. Without knowing much more, I would lean to putting the new box on it's own IP subnet and then route it through the accesslist

Anyone else got a cleaner idea?

Mike S
 
Without knowing your box, I can tell you most of these boxes have a setting to filter on Ip addresses, but you will have to disable DHCP if you are using it. You can also write extended access-list to filter on HTTP, PORT #'s , specific IP addresses. Just remember if you put deny statements first in an access-list you must put an "access-list xxx permit IP any any" at the end of the list or the "implicit deny" will deny all users.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top