Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements
Webcast-Catalyst9k
New Member

I'm attempting to create an access list

I'm attempting to create an access list that allows traffic to the internet but denies access to any internal networked ip space.  This will be applied to a vlan interface as an "in".  My thought is that it should deny traffic to the 172."30,29,28" space from any but then permit them to any other address.  Can someone please confirm or refute my acl list understanding?  Thanks in advance.  - Kyle

ip access-list extended TEST-IN

 deny ip any 172.30.0.0 0.0.255.255

 deny ip any 172.29.0.0 0.0.255.255

 deny ip any 172.28.0.0 0.0.255.255

 permit ip host 10.20.0.6 any

Everyone's tags (1)
2 REPLIES
New Member

Hi,That should work as you

Hi,

That should work as you intend.

This will permit 10.20.0.6 access to any location. The exception being that any IP including 10.20.0.6 will also be denied access to 172.28-30.0.0.

 

New Member

Hi Kyle, The ACL rules would

Hi Kyle,

 

The ACL rules would work fine. but consider the following guidelines when creating ACL on IOS.

 

1) if you are permitting 1 host or a smaller domain and denying a subnet, then use the permit before denying.

 

Example:

ip access-list extended TEST-IN

 permit ip host 10.20.0.6 any

 deny ip any 172.30.0.0 0.0.255.255

 deny ip any 172.29.0.0 0.0.255.255

 deny ip any 172.28.0.0 0.0.255.255

 

And also, this would permit the 10.20.0.6 to the 172.30/29/28 as well.

Reason: ACL works on hit and trial basis. If match is found, it would not go beyond.. so to minimize the overhead and cpu usage, prefer to get smaller rules on top before major denies/permits.

 

2) In case of denies.

 

example:

ip access-list extended TEST-IN

  deny ip host 10.20.0.6 any   <<<<<<<<<<<<<< the smaller entries come first.

  permit ip any 172.30.0.0 0.0.255.255

  permit ip any 172.29.0.0 0.0.255.255

  permit ip any 172.28.0.0 0.0.255.255

 

Saves computation time and processing as well.

 

Hope that helps.

Abhishek

CCIE 35269

 

 

Regards, Abhishek Purohit CCIE-S- 35269
104
Views
0
Helpful
2
Replies
CreatePlease to create content