Ganesh Hariharan Sun, 07/25/2010 - 23:59

if i apply acl on some router a, and i block one ip from internal network, then i use nat on that router,nat will change that ip to public ip ,then how can i block that using my previous access list?


If you apply acl in local lan interface for private ip if the source match for deny then it will not go for internet traffic for natting.

Panos Kampanakis Mon, 07/26/2010 - 07:25

If you know what the internal private ip will be translated to you can create a new ACL for the inbound traffic applied on the outside interface. But that will work if the internal ip is natted and if it is not overload PATted to the global.



