Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

vat
New Member

cat 4006, L3 engine and ACL

Hello

I want to setup some ACL on my L3 engine. The tests i ve done so far are all failed, the acl simply doesnt "work", the host i want to restrict is still available from any source and can reach any destination too.

I never had any error messages during my tests so i came to the conclusion that something was far beyond my comprehension. Below is some cut&paste from my config.

If anyone has any idea, thanks in advance.

######

sh ver

WS-C4006 Software, Version NmpSW: 6.3(1)

Copyright (c) 1995-2001 by Cisco Systems, Inc.

NMP S/W compiled on Jul 24 2001, 12:55:29

GSP S/W compiled on Jul 24 2001, 10:36:29

System Bootstrap Version: 5.4(1)

Hardware Version: 1.4 Model: WS-C4006 Serial #: JAB050608TU

Mod Port Model Serial # Versions

--- ---- ---------- -------------------- ---------------------------------

1 2 WS-X4013 JAB050608TU Hw : 1.4

Gsp: 6.3(1.0)

Nmp: 6.3(1)

2 18 WS-X4418 JAE05040018 Hw : 1.0

3 34 WS-X4232-L3 JAB053206QH Hw : 1.7

4 14 WS-X4412-2GB-T JAE04470AAQ Hw : 1.0

6 48 WS-X4148-RJ JAE044101EK Hw : 2.3

DRAM FLASH NVRAM

Module Total Used Free Total Used Free Total Used Free

------ ------- ------- ------- ------- ------- ------- ----- ----- -----

1 65536K 34607K 30929K 16384K 8720K 7664K 480K 224K 256K

Uptime is 385 days, 7 hours, 43 minutes

######

sh ver

Cisco Internetwork Operating System Software

IOS (tm) L3 Switch/Router Software (CAT4232-IN-M), Version 12.0(10)W5(18f) RELEASE SOFTWARE

Copyright (c) 1986-2000 by cisco Systems, Inc.

Compiled Mon 04-Dec-00 22:07 by integ

Image text-base: 0x60010928, data-base: 0x605F6000

ROM: System Bootstrap, Version 12.0(7)W5(15b) RELEASE SOFTWARE

C4k6-L3 uptime is 1 year, 3 weeks, 4 days, 14 hours, 30 minutes

System restarted by power-on at 01:06:02 EST Sun Dec 23 2001

Running default software

cisco Cat4232L3 (R5000) processor with 57344K/8192K bytes of memory.

R5000 processor, Implementation 35, Revision 2.1

Last reset from power-on

1 FastEthernet/IEEE 802.3 interface(s)

4 Gigabit Ethernet/IEEE 802.3z interface(s)

123K bytes of non-volatile configuration memory.

16384K bytes of Flash internal SIMM (Sector size 256K).

Configuration register is 0x2

#############################

interface Port-channel1.5

description blabla

encapsulation dot1Q 5

ip address 10.0.0.254 255.255.255.0

ip access-group 2001 in

ip access-group 2002 out

no ip redirects

no ip directed-broadcast

no ip proxy-arp

no cdp enable

!

access-list 2001 permit tcp any any established

access-list 2001 permit ip host 10.1.1.1 host 10.0.0.1

access-list 2001 deny ip any host 10.0.0.1

access-list 2001 permit ip any any

!

access-list 2002 permit tcp any any established

access-list 2002 deny ip host 10.0.0.1 any

access-list 2002 permit ip any any

1 ACCEPTED SOLUTION

Accepted Solutions
Cisco Employee

Re: cat 4006, L3 engine and ACL

ACLs are not supported on Gigabit EtherChannel (GEC) interfaces. You'll need to redo the configs to make ACLs work. The following page should help

http://www.cisco.com/warp/public/473/28.html#access-list_ws

1 REPLY
Cisco Employee

Re: cat 4006, L3 engine and ACL

ACLs are not supported on Gigabit EtherChannel (GEC) interfaces. You'll need to redo the configs to make ACLs work. The following page should help

http://www.cisco.com/warp/public/473/28.html#access-list_ws

85
Views
5
Helpful
1
Replies
CreatePlease login to create content