Unsolved

This post is more than 5 years old

3 Posts

7004

April 1st, 2005 16:00

PowerConnect 6024 Access-List not working

Hi;

I'm configuring a new 6024 and I can't seem to get the access-list to function.

I'm connected to the outside on port 24.

I have two web servers that I tried to block access to:

38.116.36.11 and 12 - there's not a permit for them in the following access-list for port 80, yet I can still get to them.

Nothing I do seems to make any difference, it's like the access-list is not being applied by port 24.

Any suggestions?

Thanks

Fred

interface ethernet g24

speed 1000

exit

interface ethernet g24

duplex full

exit

interface ethernet g24

no negotiation

exit

interface ethernet g24

ip address 38.112.27.186 255.255.255.252

exit

interface vlan 1

ip address 38.116.36.1 255.255.255.192

exit

interface ip 38.112.27.186

directed-broadcast

exit

interface ip 38.116.36.1

directed-broadcast

exit

ip route 0.0.0.0 0.0.0.0 38.112.27.185

qos advanced

ip access-list "1"

permit any 24.172.5.150 255.255.255.255 any

permit-tcp any any 38.116.36.1 255.255.255.255 23

permit-tcp any any 38.116.36.2 255.255.255.255 23

permit-tcp any any 38.116.36.1 255.255.255.255 80

permit-tcp any any 38.116.36.2 255.255.255.255 80

permit-udp any any 38.116.36.11 255.255.255.255 53

permit-udp any any 38.116.36.12 255.255.255.255 53

permit-tcp any any 38.116.36.20 255.255.255.255 80

permit-tcp any any 38.116.36.20 255.255.255.255 554

permit-tcp any any 38.116.36.20 255.255.255.255 1755

permit-udp any any 38.116.36.20 255.255.255.255 80

permit-udp any any 38.116.36.20 255.255.255.255 554

permit-udp any any 38.116.36.20 255.255.255.255 1755

permit-udp any any 38.116.36.3 255.255.255.255 80

permit-udp any any 38.116.36.3 255.255.255.255 554

permit-udp any any 38.116.36.3 255.255.255.255 1755

permit-tcp any any 38.116.36.3 255.255.255.255 80

permit-tcp any any 38.116.36.3 255.255.255.255 554

permit-tcp any any 38.116.36.3 255.255.255.255 1755

permit-udp any any 38.116.36.4 255.255.255.255 80

permit-udp any any 38.116.36.4 255.255.255.255 554

permit-udp any any 38.116.36.4 255.255.255.255 1755

permit-tcp any any 38.116.36.4 255.255.255.255 80

permit-tcp any any 38.116.36.4 255.255.255.255 554

permit-tcp any any 38.116.36.4 255.255.255.255 1755

permit-udp any any 38.116.36.5 255.255.255.255 80

permit-udp any any 38.116.36.5 255.255.255.255 554

permit-udp any any 38.116.36.5 255.255.255.255 1755

permit-tcp any any 38.116.36.5 255.255.255.255 80

permit-tcp any any 38.116.36.5 255.255.255.255 554

permit-tcp any any 38.116.36.5 255.255.255.255 1755

permit-udp any any 38.116.36.6 255.255.255.255 80

permit-udp any any 38.116.36.6 255.255.255.255 554

permit-udp any any 38.116.36.6 255.255.255.255 1755

permit-tcp any any 38.116.36.6 255.255.255.255 80

permit-tcp any any 38.116.36.6 255.255.255.255 554

permit-tcp any any 38.116.36.6 255.255.255.255 1755

permit-udp any any 38.116.36.7 255.255.255.255 80

permit-udp any any 38.116.36.7 255.255.255.255 554

permit-udp any any 38.116.36.7 255.255.255.255 1755

permit-tcp any any 38.116.36.7 255.255.255.255 80

permit-tcp any any 38.116.36.7 255.255.255.255 554

permit-tcp any any 38.116.36.7 255.255.255.255 1755

permit-udp any any 38.116.36.8 255.255.255.255 80

permit-udp any any 38.116.36.8 255.255.255.255 554

permit-udp any any 38.116.36.8 255.255.255.255 1755

permit-tcp any any 38.116.36.8 255.255.255.255 80

permit-tcp any any 38.116.36.8 255.255.255.255 554

permit-tcp any any 38.116.36.8 255.255.255.255 1755

deny any any any

exit

interface ethernet g24

service-acl input "1"

exit

aaa authentication login default local

 

 

3 Posts

April 4th, 2005 15:00

Update:
Ok, it appears that the access-list does work, however I still get access on port 80 to the hosts at 38.116.36.11 & 12 with the access-list in place.  However the access-list does block the ports for other services such as VNC (If I drop the access-list I can use VNC to these servers, if I apply the access-list I cannot).
Why is it allowing port 80?
Here's the current access-list....
console# show access-list 1
IP access list 1
    permit  tcp any any 38.116.36.11 255.255.255.255 20
    permit  tcp any any 38.116.36.11 255.255.255.255 21
    permit  tcp any any 38.116.36.12 255.255.255.255 20
    permit  tcp any any 38.116.36.12 255.255.255.255 21
    permit  tcp any any 38.116.36.1 255.255.255.255 23
    permit  tcp any any 38.116.36.2 255.255.255.255 23
    permit  tcp any any 38.116.36.1 255.255.255.255 80
    permit  tcp any any 38.116.36.2 255.255.255.255 80
    permit  udp any any 38.116.36.11 255.255.255.255 53
    permit  udp any any 38.116.36.12 255.255.255.255 53
    permit  tcp any any 38.116.36.20 255.255.255.255 80
    permit  tcp any any 38.116.36.20 255.255.255.255 554
    permit  tcp any any 38.116.36.20 255.255.255.255 1755
    permit  udp any any 38.116.36.20 255.255.255.255 80
    permit  udp any any 38.116.36.20 255.255.255.255 554
    permit  udp any any 38.116.36.20 255.255.255.255 1755
    permit  udp any any 38.116.36.3 255.255.255.255 80
    permit  udp any any 38.116.36.3 255.255.255.255 554
    permit  udp any any 38.116.36.3 255.255.255.255 1755
    permit  tcp any any 38.116.36.3 255.255.255.255 80
    permit  tcp any any 38.116.36.3 255.255.255.255 554
    permit  tcp any any 38.116.36.3 255.255.255.255 1755
    permit  udp any any 38.116.36.4 255.255.255.255 80
    permit  udp any any 38.116.36.4 255.255.255.255 554
    permit  udp any any 38.116.36.4 255.255.255.255 1755
    permit  tcp any any 38.116.36.4 255.255.255.255 80
    permit  tcp any any 38.116.36.4 255.255.255.255 554
    permit  tcp any any 38.116.36.4 255.255.255.255 1755
    permit  udp any any 38.116.36.5 255.255.255.255 80
    permit  udp any any 38.116.36.5 255.255.255.255 554
    permit  udp any any 38.116.36.5 255.255.255.255 1755
    permit  tcp any any 38.116.36.5 255.255.255.255 80
    permit  tcp any any 38.116.36.5 255.255.255.255 554
    permit  tcp any any 38.116.36.5 255.255.255.255 1755
    permit  udp any any 38.116.36.6 255.255.255.255 80
    permit  udp any any 38.116.36.6 255.255.255.255 554
    permit  udp any any 38.116.36.6 255.255.255.255 1755
    permit  tcp any any 38.116.36.6 255.255.255.255 80
    permit  tcp any any 38.116.36.6 255.255.255.255 554
    permit  tcp any any 38.116.36.6 255.255.255.255 1755
    permit  udp any any 38.116.36.7 255.255.255.255 80
    permit  udp any any 38.116.36.7 255.255.255.255 554
    permit  udp any any 38.116.36.7 255.255.255.255 1755
    permit  tcp any any 38.116.36.7 255.255.255.255 80
    permit  tcp any any 38.116.36.7 255.255.255.255 554
    permit  tcp any any 38.116.36.7 255.255.255.255 1755
    permit  udp any any 38.116.36.8 255.255.255.255 80
    permit  udp any any 38.116.36.8 255.255.255.255 554
    permit  udp any any 38.116.36.8 255.255.255.255 1755
    permit  tcp any any 38.116.36.8 255.255.255.255 80
    permit  tcp any any 38.116.36.8 255.255.255.255 554
    permit  tcp any any 38.116.36.8 255.255.255.255 1755
No Events found!

Top