×

Warning message

  • Cisco Support Forums is in Read Only mode while the site is being migrated.
  • Cisco Support Forums is in Read Only mode while the site is being migrated.

Access-list with DHCP

Unanswered Question
May 30th, 2012
User Badges:

Hello Cisco support community,


I have a question regarding ACL with DHCP:

I have cisco 881 routers:

     - VLAN 1 (FastEthernet 0, 1, 2 and 3): IP address 172.20.0.1/16

     - FastEthernet 4 (connected to another network): IP address receivede from a DHCP server.


These router will be installed on different sites where I don't have access to the DHCP server: I don't know the IP address that FA4 will receive.

I want to make an inbound ACL to allow access to 1 host in the FA4 network to a specific port.


interface fa 4
ip access-group  FILTER in

ip access-list FILTER

permit tcp host [host IP] [IP FA4] eq [port]

How can I do that kind of ACL if I don't know the IP address of FA4 in advance ?


Thank you !


Nicolas

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 5 (1 ratings)
Loading.
johnlloyd_13 Sun, 06/03/2012 - 08:55
User Badges:
  • Blue, 1500 points or more

hi nicolas,


if FE4 is receving dynamic IP from DHCP, you could put your ACL under VLAN 1 SVI instead.

Jeff Van Houten Sun, 06/03/2012 - 10:09
User Badges:
  • Silver, 250 points or more

Why not just put the acl on the server itself? Windows and Linux both have port filters you could activate and allow only the traffic you specify inbound.


Sent from Cisco Technical Support iPad App

Tagir Temirgaliyev Sun, 06/03/2012 - 22:01
User Badges:
  • Silver, 250 points or more

Hi


you will need to enable DHCP to get address


ip access-list FILTER

permit udp any any eq 67

permit udp any any eq 68

permit tcp host [host IP] 172.20.0.0 0.0.255.255 eq [port]


this will enable to get dhcp address

and comunication from [host IP] to your network 172.20.0.0 0.0.255.255

dont forget to rate post if it helps

Actions

This Discussion