AS SOON AS I APPLY THIS TO MY INCOMING SERIAL INTERFACE I CANNOT SURF THE INTERNET ANYMORE. CAN SOMEONE PLEASE HELP ME.
ASSUMING THAT 197.20.115.137/29 IS MY PUBLIC ADDRESS ON MY ROUTER
I HAVE APPLIED THIS ACCESS LIST TO ALL TRAFFIC COMING IN FROM THE INTERNET INTO MY SERIAL INTERFACE
AT THIS STAGE NO ACCESS LIST HAS BEEN APPLIED TO THE ETHERNET INTERFACE RESTRICTING MY INTERNAL USERS.
access-list 100 deny ip 197.20.115.136 0.0.0.7 any log
access-list 100 deny ip host 197.20.115.137 host 197.20.115.137 log
access-list 100 deny ip 127.0.0.0 0.255.255.255 any log
access-list 100 deny ip 10.0.0.0 0.255.255.255 any log
access-list 100 deny ip 172.16.0.0 0.15.255.255 any log
access-list 100 deny ip 192.0.2.0 0.0.255.255 any log
access-list 100 deny ip 192.168.0.0 0.0.255.255 any log
access-list 100 deny ip 169.254.0.0 0.0.255.255 any log
access-list 100 deny ip 224.0.0.0 15.255.255.255 any log
access-list 100 deny ip 240.0.0.0 7.255.255.255 any log
access-list 100 deny ip 248.0.0.0 7.255.255.255 any log
access-list 100 deny ip 255.0.0.0 0.255.255.255 any log
access-list 100 deny ip host 0.0.0.0 any log
access-list 100 deny ip host 255.255.255.255 any log
access-list 100 deny ip 0.0.0.0 0.255.255.255 any log
access-list 100 deny ip any host 197.20.115.255 log
access-list 100 deny ip any host 197.20.115.0 log
access-list 100 deny icmp any any echo log
access-list 100 deny icmp any any redirect log
access-list 100 deny icmp any any mask-request log
access-list 100 permit icmp any 197.20.115.137 0.0.0.7
access-list 100 permit tcp any any established
access-list 100 permit tcp any any eq 80 log
access-list 100 permit tcp any any eq 53 log
access-list 100 permit udp any any eq 53 log
access-list 100 permit tcp any any eq 25 log
access-list 100 permit tcp any any eq 110 log
access-list 100 permit tcp any any eq 113 log
access-list 100 permit tcp any any eq 443 log
access-list 100 permit tcp any any eq 5631 log
access-list 100 permit tcp any any eq 5632 log
access-list 100 permit tcp any any eq 1352 log
access-list 100 permit tcp any any eq 1863 log
access-list 100 deny ip any any log
ASSUMING THAT 197.20.115.137/29 IS MY PUBLIC ADDRESS ON MY ROUTER
I HAVE APPLIED THIS ACCESS LIST TO ALL TRAFFIC COMING IN FROM THE INTERNET INTO MY SERIAL INTERFACE
AT THIS STAGE NO ACCESS LIST HAS BEEN APPLIED TO THE ETHERNET INTERFACE RESTRICTING MY INTERNAL USERS.
access-list 100 deny ip 197.20.115.136 0.0.0.7 any log
access-list 100 deny ip host 197.20.115.137 host 197.20.115.137 log
access-list 100 deny ip 127.0.0.0 0.255.255.255 any log
access-list 100 deny ip 10.0.0.0 0.255.255.255 any log
access-list 100 deny ip 172.16.0.0 0.15.255.255 any log
access-list 100 deny ip 192.0.2.0 0.0.255.255 any log
access-list 100 deny ip 192.168.0.0 0.0.255.255 any log
access-list 100 deny ip 169.254.0.0 0.0.255.255 any log
access-list 100 deny ip 224.0.0.0 15.255.255.255 any log
access-list 100 deny ip 240.0.0.0 7.255.255.255 any log
access-list 100 deny ip 248.0.0.0 7.255.255.255 any log
access-list 100 deny ip 255.0.0.0 0.255.255.255 any log
access-list 100 deny ip host 0.0.0.0 any log
access-list 100 deny ip host 255.255.255.255 any log
access-list 100 deny ip 0.0.0.0 0.255.255.255 any log
access-list 100 deny ip any host 197.20.115.255 log
access-list 100 deny ip any host 197.20.115.0 log
access-list 100 deny icmp any any echo log
access-list 100 deny icmp any any redirect log
access-list 100 deny icmp any any mask-request log
access-list 100 permit icmp any 197.20.115.137 0.0.0.7
access-list 100 permit tcp any any established
access-list 100 permit tcp any any eq 80 log
access-list 100 permit tcp any any eq 53 log
access-list 100 permit udp any any eq 53 log
access-list 100 permit tcp any any eq 25 log
access-list 100 permit tcp any any eq 110 log
access-list 100 permit tcp any any eq 113 log
access-list 100 permit tcp any any eq 443 log
access-list 100 permit tcp any any eq 5631 log
access-list 100 permit tcp any any eq 5632 log
access-list 100 permit tcp any any eq 1352 log
access-list 100 permit tcp any any eq 1863 log
access-list 100 deny ip any any log