Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

ACL list

Confused on the ACL, when to use tcp host and IP host in the access list I.e permit tcp host or IP host.

Everyone's tags (1)
4 REPLIES
VIP Purple

"tcp" is what it says, just

"tcp" is what it says, just TCP. If you use "permit ip ..." in your ACL you allow all IP-protocols which is TCP/UDP/ICMP/GRE/ESP and so on.


--
Don't stop after you've improved your network! Improve the world by lending money to the working poor: http://www.kiva.org/invitedby/karsteni
New Member

Sorry if I was not clear. I

Sorry if I was not clear. I have seen others using permit ip host 172.xx.xx.xx 23 host 192.168.xx.0 2000 and some use it like

permit tcp 172.xx.xx.xx 23 host 192.168.xx.0 2000 so that what confuses me. there maybe an explanation for me to better understand.

Let me ask a question about a firewall rule. Which answer is right and why? Permit tcp host 10.10.10.254 eq 80 host 10.10.0.2 eq 5000 Permit IP host 10.10.10.254 eq host 10.10.0.2 eq 5000 Which would the right way to use and why?
VIP Purple

do you have a real example? I

do you have a real example? I assume that the 23 and 2000 should be ports which were allowed with "tcp" when you also use the keyword "eq". With "ip" there are no ports allowed. So it would be really important to know what you are referring to.

--
Don't stop after you've improved your network! Improve the world by lending money to the working poor: http://www.kiva.org/invitedby/karsteni
New Member

Sorry if I was not clear. I

Sorry if I was not clear. I have seen others using permit ip host 172.xx.xx.xx 23 host 192.168.xx.0 2000 and some use it like

permit tcp 172.xx.xx.xx 23 host 192.168.xx.0 2000 so that what confuses me. there maybe an explanation for me to better understand.

52
Views
0
Helpful
4
Replies