Book now with code EOY2025
DANMOH009 wrote: » Now the router i am put the acl has a serial interface 171.10.0.0/30 connected, and two sub interfaces 192.168.20.0/25 and 192.168.20.128/25, ip access-list extended TELNET remark this permits telnet access for managers pcs on both tech and cserv permit tcp 192.168.10.0 0.0.0.127 host 192.168.20.1 eq telnet permit tcp 192.168.10.0 0.0.0.127 host 192.168.20.129 eq telnet permit tcp 192.168.10.0 0.0.0.127 host 171.10.0.2 eq telnet
DANMOH009 wrote: » The ACL doesnt work, so for example if i want to telnet from a network that is restricted it wont restrict it.
Now the router i am put the acl has a serial interface 171.10.0.0/30 connected, and two sub interfaces 192.168.20.0/25 and 192.168.20.128/25.. i am applying the ACL to the Fa0/0 interface
is this allowed and will it work?
DANMOH009 wrote: » I originally only applied it to Fa interface i now applied it to serial alos. Do i need to apply to the sub interfaces??
DANMOH009 wrote: » CservRouter#show access-lists Extended IP access list TELNET permit tcp 192.168.10.0 0.0.0.127 host 192.168.20.1 eq telnet permit tcp 192.168.10.0 0.0.0.127 host 192.168.20.129 eq telnet permit tcp 192.168.10.0 0.0.0.127 host 171.10.0.2 eq telnet permit tcp 192.168.20.0 0.0.0.127 host 192.168.20.129 eq telnet permit tcp 192.168.20.0 0.0.0.127 host 192.168.20.129 deny tcp any any eq telnet permit ip any any
DANMOH009 wrote: » I dont understand, they all have IP addresses assigned, is it basically just really really messed up.
show run wrote: interface FastEthernet0/0 no ip address ip access-group TELNET in duplex auto speed auto ! interface FastEthernet0/0.1 encapsulation dot1Q 10 ip address 192.168.20.1 255.255.255.128 ! interface FastEthernet0/0.2 encapsulation dot1Q 20 ip address 192.168.20.129 255.255.255.128 !
DANMOH009 wrote: » So i know its petty but why the different messages? thanks in advance, last question i promise
Use code EOY2025 to receive $250 off your 2025 certification boot camp!