Hi, I have a Cisco 1720 router, and I'm looking to block my internal clients from accessing certain IP addresses (such as AOL instant messenger and yahoo messenger). I have done very little work with ACLs, I am assuming this is the way to do it. Here is an excerpt from my config file:
!
interface FastEthernet0
description connected to EthernetLAN
ip address 192.168.200.2 255.255.255.0
ip access-group 100 in
no ip directed-broadcast
ip nat inside
ip inspect FastEthernet_0 in
no cdp enable
!
router rip
version 2
passive-interface Serial0
network 192.168.200.0
no auto-summary
!
ip nat pool GBT_1720-natpool-0 64.9.11.141 64.9.11.141 netmask 255.255.255.252
ip nat inside source list 1 pool GBT_1720-natpool-0 overload
ip classless
ip route 0.0.0.0 0.0.0.0 Serial0
no ip http server
!
access-list 1 permit 192.168.200.0 0.0.0.255
access-list 3 permit 68.32.207.246
access-list 3 permit 207.155.252.47
access-list 3 permit 207.155.248.12
access-list 3 permit 207.155.248.4
access-list 3 permit 207.155.248.7
access-list 3 permit 68.85.114.204
access-list 3 permit 207.155.252.18
access-list 3 permit 207.155.252.72
access-list 3 permit any
access-list 100 permit ip any any
access-list 101 permit icmp any any
no cdp run
Thanks for any help anyone can give me.
!
interface FastEthernet0
description connected to EthernetLAN
ip address 192.168.200.2 255.255.255.0
ip access-group 100 in
no ip directed-broadcast
ip nat inside
ip inspect FastEthernet_0 in
no cdp enable
!
router rip
version 2
passive-interface Serial0
network 192.168.200.0
no auto-summary
!
ip nat pool GBT_1720-natpool-0 64.9.11.141 64.9.11.141 netmask 255.255.255.252
ip nat inside source list 1 pool GBT_1720-natpool-0 overload
ip classless
ip route 0.0.0.0 0.0.0.0 Serial0
no ip http server
!
access-list 1 permit 192.168.200.0 0.0.0.255
access-list 3 permit 68.32.207.246
access-list 3 permit 207.155.252.47
access-list 3 permit 207.155.248.12
access-list 3 permit 207.155.248.4
access-list 3 permit 207.155.248.7
access-list 3 permit 68.85.114.204
access-list 3 permit 207.155.252.18
access-list 3 permit 207.155.252.72
access-list 3 permit any
access-list 100 permit ip any any
access-list 101 permit icmp any any
no cdp run
Thanks for any help anyone can give me.