Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 
New Member

Need suggestion


Iam having two internet links (512 & 256kbps).

I had configured the FE0/0 with the internet pool ip.

Now I want to configure other fe0/1 using my internal Lan ip.

There will be no firewall connected between these links.

Pls suggest me to more secure my network by configuring only on the router which should not take any attacks on my LAN Zone.


Super Bronze

Re: Need suggestion

If from what you describe, you only want communication between your internet pool devices attached to fe0/0 and your internal LAN devices connected to fe0/1, you can define an ACL to only permit traffic between your IP pool and your internal addresses (don't exclude traffic between your Internet pool and the Internet). Doing this will protect your internal LAN from direct attacks from the Internet, but if someone "captures" one of your Internet pool hosts, they would have access to your LAN.

The latter is harder to control, but the ACL can be expanded to what type of traffic is permitted between your Internet pool devices and the LAN.

Many Cisco routers support a "firewall" feature set, that within their software, allows them to control traffic much like a dedicated firewall appliance.


I'm assuming from your description you have a separate Internet device network segment, but if you mean you have just a pool of Internet addresses and intend for your internal LAN to use those, i.e. the internal LAN desires to communicate with the Internet, things differ.

If this is the case, you NAT between the Internet and your internal LAN. Again, an ACL would be used to control what traffic is allowed to flow in or out. One helpful rule is to allow most TCP outbound, but only accept TCP inbound with the established bit set.

Here too, you would benefit more from having the firewall feature set.

Cisco has some free configuration tools that are provided with some of their routers. They make some of these common complex configuration simple to implement.

Re: Need suggestion


Nat is a security measure, by configuring Nat , you will ensure that Traffic are not permitted unless its initiated from your LAN Pool.

As Advance security measur, u can configure(Reflexive Access-list).



CreatePlease to create content