Security Basics mailing list archives

RE: router access control list


From: "David Gillett" <gillettdavid () fhda edu>
Date: Wed, 25 Oct 2006 17:26:07 -0700

  Every access-list ends with a "deny" of all remaining unmatched 
traffic.  It might not be obvious that this is also true of access
lists that you haven't created yet!
  So make sure that you create the access list and *then* bind it
to the interface, NOT the other way around....

  Except when you use "any any" as source and destination, any
access list will properly apply to only one direction of traffic.
So I have access lists files with comments at the top that say 
things like "into interface = FROM this vlan" as a reminder.

Dave Gillett
 

-----Original Message-----
From: listbounce () securityfocus com 
[mailto:listbounce () securityfocus com] On Behalf Of apaez1084 () gmail com
Sent: Wednesday, October 25, 2006 1:46 PM
To: security-basics () securityfocus com
Subject: Re: router access control list

thank for the information. it been great help. But, it looks 
easier than it is. 

i just made the router go crazy!!!

let me c if maybe giving an idea of what the network looks 
like someone can help. 

i got one router/dsl modem. its actually a cisco 800 series 
(837 not 827). this is connecteed to a hub that has all the 
computers on to their. 

router/modem is 192.168.0.1 

and the 15 computer adresses go from 192.168.0.0 
-192.168.0.255. not in any specific order.

im guessing router is interface E0 when making the access 
list. or is it. because any command i put blocks the internet 
weatehr is in out out. 
im guessing im applying all the access list to the routers 
interface E0. the one that comes in and out. 

any one can help me with this much information. if you might 
need a little more just ask. 

thanks 

--------------------------------------------------------------
-------------
This list is sponsored by: Norwich University

EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE 
The NSA has designated Norwich University a center of 
Academic Excellence in Information Security. Our program 
offers unparalleled Infosec management education and the case 
study affords you unmatched consulting experience. 
Using interactive e-Learning technology, you can earn this 
esteemed degree, without disrupting your career or home life.

http://www.msia.norwich.edu/secfocus
--------------------------------------------------------------
-------------



---------------------------------------------------------------------------
This list is sponsored by: Norwich University

EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE
The NSA has designated Norwich University a center of Academic Excellence 
in Information Security. Our program offers unparalleled Infosec management 
education and the case study affords you unmatched consulting experience. 
Using interactive e-Learning technology, you can earn this esteemed degree, 
without disrupting your career or home life.

http://www.msia.norwich.edu/secfocus
---------------------------------------------------------------------------


Current thread: