Book now with code EOY2025
ninjaz wrote: I'm having a problem with an ACL that I'm trying to create. I know the "access xxx out" is for traffic going out of the interface and the opposite for the incoming interface, however the only thing that seems to work is if I put it on the outgoing interface. I want to block all traffic going to a server that I have besides allowing the traffic to go to the specific ports, such as Windows RDP, and Windows file sharing. When I create this list it seems to not allow any traffic at all, however when I set it to the outgoing side it seems to block everything just fine and I'm not sure why. This is what I have for my outgoing... permit tcp 10.0.0.0 0.0.0.255 host 10.0.0.18 eq 3389 (821 matches) permit udp 10.0.0.0 0.0.0.255 host 10.0.0.18 eq 3389 permit tcp 141.209.0.0 0.0.255.255 host 10.0.0.18 eq 3389 (230 matches) permit udp 10.0.0.0 0.0.0.255 host 10.0.0.18 eq netbios-ns (74 matches) permit udp 10.0.0.0 0.0.0.255 host 10.0.0.18 eq netbios-dgm permit tcp 10.0.0.0 0.0.0.255 host 10.0.0.18 eq 139 (15412466 matches) permit tcp 10.0.0.0 0.0.0.255 host 10.0.0.18 eq 445 (4889329 matches) permit tcp 10.0.0.16 0.0.0.7 any eq www permit tcp 10.0.0.16 0.0.0.7 any eq 443 permit tcp any 10.0.0.16 0.0.0.7 eq www (432 matches) permit tcp any 10.0.0.16 0.0.0.7 eq 443 (156 matches) permit udp host 10.0.0.11 host 10.0.0.18 eq snmp (46192 matches) permit udp host 10.0.0.11 host 10.0.0.18 eq snmptrap permit tcp host 10.0.0.11 host 10.0.0.18 eq domain permit tcp host 10.0.0.19 host 10.0.0.18 eq domain permit udp host 10.0.0.11 host 10.0.0.18 eq domain (51 matches) permit udp host 10.0.0.19 host 10.0.0.18 eq domain permit ip host 10.0.0.19 any permit ip any host 10.0.0.19 (101439 matches) permit icmp any any (10521 matches) Thanks in advance.
ninjaz wrote: Ok, so it must be ignorance on my part then because from I had understood as applying the ACL to the inbound/outbound interface was that the inbound is traffic coming into the interface and the outbound was traffic coming out of the computers behind the interface. The thing that was confusing me was that when I applied to to the outbound interface I was not allowing the computers to make the outgoing connection as opposed to applying it to the inbound interface and allow outside computers to make that connection in the first place. I hope that made sense! :
Use code EOY2025 to receive $250 off your 2025 certification boot camp!