Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

xbw
New Member

About 2950 acl configuration

I have a c2950 and want to config acl. I enter INTERFACE MODE and issue IP ACCESS-GROUP command ,But system prompt no this command . how can I do. Please help me . Issuing show ver command.Message as fallows.

Cisco Internetwork Operating System Software

IOS (tm) C2950 Software (C2950-I6K2L2Q4-M), Version 12.1(22)EA6, RELEASE SOFTWARE (fc1)

Copyright (c) 1986-2005 by cisco Systems, Inc.

Compiled Fri 21-Oct-05 02:22 by yenanh

Image text-base: 0x80010000, data-base: 0x80676000

ROM: Bootstrap program is C2950 boot loader

tycib_sw29_f2office2 uptime is 3 minutes

System returned to ROM by power-on

System image file is "flash:/c2950-i6k2l2q4-mz.121-22.EA6.bin"

This product contains cryptographic features and is subject to United

States and local country laws governing import, export, transfer and

use. Delivery of Cisco cryptographic products does not imply

third-party authority to import, export, distribute or use encryption.

Importers, exporters, distributors and users are responsible for

compliance with U.S. and local country laws. By using this product you

agree to comply with applicable laws and regulations. If you are unable

to comply with U.S. and local laws, return this product immediately.

A summary of U.S. laws governing Cisco cryptographic products may be found at:

http://www.cisco.com/wwl/export/crypto/tool/stqrg.html

If you require further assistance please contact us by sending email to

export@cisco.com.

cisco WS-C2950-24 (RC32300) processor (revision R0) with 19973K bytes of memory.

Processor board ID FOC0935Z7SN

Last reset from system-reset

Running Standard Image

24 FastEthernet/IEEE 802.3 interface(s)

32K bytes of flash-simulated non-volatile configuration memory.

Base ethernet MAC Address: 00:15:62:63:5D:C0

Motherboard assembly number: 73-5781-13

Power supply part number: 34-0965-01

Motherboard serial number: FOC09343GDK

Power supply serial number: DAB0930DP48

Model revision number: R0

Motherboard revision number: A0

Model number: WS-C2950-24

System serial number: FOC0935Z7SN

Configuration register is 0xF

8 REPLIES

Re: About 2950 acl configuration

Hi There,

Your switch WS-C2950-24, is a switch with standard image i.e SMI. This image doenot support ACL's and that's why its not working. You should have a 2950 with EMI to run ACLs. This switch is not upgradable to EMI so you really cannot use ACLs on this :(.

http://www.cisco.com/en/US/products/hw/switches/ps628/products_data_sheet09186a00801cfb71.html

regards,

-amit singh

Re: About 2950 acl configuration

Hi XBW,

On which interface you are tying to apply the ACL.

Also I hope you might have tried the whole command "ip access-group in"

Can you post the output of error which you get when you try to apply ths command.

Regards,

Ankur

xbw
New Member

Re: About 2950 acl configuration

I upgraded my c2950 image. AS fallows:

.................................

System image file is "flash:/c2950-i6k2l2q4-mz.121-22.EA6.bin"

.................................

Last reset from system-reset

Running Standard Image

xbw
New Member

Re: About 2950 acl configuration

I upgraded my c2950 image. AS fallows:

.................................

System image file is "flash:/c2950-i6k2l2q4-mz.121-22.EA6.bin"

.................................

Last reset from system-reset

Running Standard Image

.....................................

please see my detail configurations in attachments.

xbw
New Member

Re: About 2950 acl configuration

please see my detail configurations in attachments

VIP Purple

Re: About 2950 acl configuration

Hello,

I think your problem might be the ´log´ option at the end of your access list. The ´log´ option is not supported on the switches, can you try and remove it, and then apply the access list inbound again ?

Regards,

GP

xbw
New Member

Re: About 2950 acl configuration

I remove the "log" option.but without avail.As follows:

tycib_sw29_f2office2#config t

Enter configuration commands, one per line. End with CNTL/Z.

tycib_sw29_f2office2#access-list 100 permit ip 192.168.2.0 0.0.0.255 192.168.1.0 0.0.0.255

tycib_sw29_f2office2(config)#int f0/1

tycib_sw29_f2offic(config-if)#ip access-group 12 in

^

% Invalid input detected at '^' marker.

Please help me!

VIP Purple

Re: About 2950 acl configuration

Hello,

reading though the entire post, I saw that the very first post from Amith already gave the answer: no ACL support on the SI image, and the switch is not upgradable...

Catalyst 2950 Series Q&A

http://www.cisco.com/en/US/products/hw/switches/ps628/products_qanda_item09186a008009258e.shtml

Regards,

GP

296
Views
5
Helpful
8
Replies