Configure Firewall Help

Unanswered Question
Aug 19th, 2010
User Badges:

Hi,


Currently I have 2 router runing on site to site IPSec VTI. I would need help to configure firewall to :


1. To allow private network to access internet.(I do not need to inspect the traffic going to the internet.)

2  To protect my private network from outside network.

3. Allow only my IP addresss(192.168.1.50) to access Telnet, SDM & SSH to my local router (192.168.1.1)

4. Allow only my IP address(192.168.1.50) to access Telnet, SDM & SSH via Tunnel to my remote Router(192.168.2.1)

5. Lastly the firewall ACL for VPN ( i know i need to permit port 500, Ip 50 &51 but I don;t know how to apply)


Can someone guide me on the command for the above?


Thank you so much

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
KARUPPUCHAMY MA... Thu, 08/19/2010 - 00:27
User Badges:
  • Silver, 250 points or more

Hi,


Find the suggestion from my side


//1. To allow private network to access internet.(I do not need to inspect the traffic going to the internet.)//


Either you have to do NAT on the firewall or your internet router.


//2  To protect my private network from outside network.//


IF you are going to use cisco firewall, by default all the traffic is blocked from outside network to your internal network.To achieve this, you have to configure your lan inteface security level is higher that your wan interface.


//

3. Allow only my IP addresss(192.168.1.50) to access Telnet, SDM & SSH to my local router (192.168.1.1)

4. Allow only my IP address(192.168.1.50) to access Telnet, SDM & SSH via Tunnel to my remote Router(192.168.2.1)///


This you can achieve by configure VTY access list on the router itslef


access-list 10 permit 192.168.1.50


line vty 0 4

access-class 10 in


//5. Lastly the firewall ACL for VPN ( i know i need to permit port 500, Ip 50 &51 but I don;t know how to apply)//


Are you going to place your firewal behind the router.Actually it is not a best practice.


Thanks

Samy

Actions

This Discussion