Unsolved
This post is more than 5 years old
3 Posts
0
7004
April 1st, 2005 16:00
PowerConnect 6024 Access-List not working
Hi;
I'm configuring a new 6024 and I can't seem to get the access-list to function.
I'm connected to the outside on port 24.
I have two web servers that I tried to block access to:
38.116.36.11 and 12 - there's not a permit for them in the following access-list for port 80, yet I can still get to them.
Nothing I do seems to make any difference, it's like the access-list is not being applied by port 24.
Any suggestions?
Thanks
Fred
interface ethernet g24
speed 1000
exit
interface ethernet g24
duplex full
exit
interface ethernet g24
no negotiation
exit
interface ethernet g24
ip address 38.112.27.186 255.255.255.252
exit
interface vlan 1
ip address 38.116.36.1 255.255.255.192
exit
interface ip 38.112.27.186
directed-broadcast
exit
interface ip 38.116.36.1
directed-broadcast
exit
ip route 0.0.0.0 0.0.0.0 38.112.27.185
qos advanced
ip access-list "1"
permit any 24.172.5.150 255.255.255.255 any
permit-tcp any any 38.116.36.1 255.255.255.255 23
permit-tcp any any 38.116.36.2 255.255.255.255 23
permit-tcp any any 38.116.36.1 255.255.255.255 80
permit-tcp any any 38.116.36.2 255.255.255.255 80
permit-udp any any 38.116.36.11 255.255.255.255 53
permit-udp any any 38.116.36.12 255.255.255.255 53
permit-tcp any any 38.116.36.20 255.255.255.255 80
permit-tcp any any 38.116.36.20 255.255.255.255 554
permit-tcp any any 38.116.36.20 255.255.255.255 1755
permit-udp any any 38.116.36.20 255.255.255.255 80
permit-udp any any 38.116.36.20 255.255.255.255 554
permit-udp any any 38.116.36.20 255.255.255.255 1755
permit-udp any any 38.116.36.3 255.255.255.255 80
permit-udp any any 38.116.36.3 255.255.255.255 554
permit-udp any any 38.116.36.3 255.255.255.255 1755
permit-tcp any any 38.116.36.3 255.255.255.255 80
permit-tcp any any 38.116.36.3 255.255.255.255 554
permit-tcp any any 38.116.36.3 255.255.255.255 1755
permit-udp any any 38.116.36.4 255.255.255.255 80
permit-udp any any 38.116.36.4 255.255.255.255 554
permit-udp any any 38.116.36.4 255.255.255.255 1755
permit-tcp any any 38.116.36.4 255.255.255.255 80
permit-tcp any any 38.116.36.4 255.255.255.255 554
permit-tcp any any 38.116.36.4 255.255.255.255 1755
permit-udp any any 38.116.36.5 255.255.255.255 80
permit-udp any any 38.116.36.5 255.255.255.255 554
permit-udp any any 38.116.36.5 255.255.255.255 1755
permit-tcp any any 38.116.36.5 255.255.255.255 80
permit-tcp any any 38.116.36.5 255.255.255.255 554
permit-tcp any any 38.116.36.5 255.255.255.255 1755
permit-udp any any 38.116.36.6 255.255.255.255 80
permit-udp any any 38.116.36.6 255.255.255.255 554
permit-udp any any 38.116.36.6 255.255.255.255 1755
permit-tcp any any 38.116.36.6 255.255.255.255 80
permit-tcp any any 38.116.36.6 255.255.255.255 554
permit-tcp any any 38.116.36.6 255.255.255.255 1755
permit-udp any any 38.116.36.7 255.255.255.255 80
permit-udp any any 38.116.36.7 255.255.255.255 554
permit-udp any any 38.116.36.7 255.255.255.255 1755
permit-tcp any any 38.116.36.7 255.255.255.255 80
permit-tcp any any 38.116.36.7 255.255.255.255 554
permit-tcp any any 38.116.36.7 255.255.255.255 1755
permit-udp any any 38.116.36.8 255.255.255.255 80
permit-udp any any 38.116.36.8 255.255.255.255 554
permit-udp any any 38.116.36.8 255.255.255.255 1755
permit-tcp any any 38.116.36.8 255.255.255.255 80
permit-tcp any any 38.116.36.8 255.255.255.255 554
permit-tcp any any 38.116.36.8 255.255.255.255 1755
deny any any any
exit
interface ethernet g24
service-acl input "1"
exit
aaa authentication login default local


FWBlack
3 Posts
0
April 4th, 2005 15:00
Ok, it appears that the access-list does work, however I still get access on port 80 to the hosts at 38.116.36.11 & 12 with the access-list in place. However the access-list does block the ports for other services such as VNC (If I drop the access-list I can use VNC to these servers, if I apply the access-list I cannot).
Why is it allowing port 80?
Here's the current access-list....
IP access list 1
permit tcp any any 38.116.36.11 255.255.255.255 20
permit tcp any any 38.116.36.11 255.255.255.255 21
permit tcp any any 38.116.36.12 255.255.255.255 20
permit tcp any any 38.116.36.12 255.255.255.255 21
permit tcp any any 38.116.36.1 255.255.255.255 23
permit tcp any any 38.116.36.2 255.255.255.255 23
permit tcp any any 38.116.36.1 255.255.255.255 80
permit tcp any any 38.116.36.2 255.255.255.255 80
permit udp any any 38.116.36.11 255.255.255.255 53
permit udp any any 38.116.36.12 255.255.255.255 53
permit tcp any any 38.116.36.20 255.255.255.255 80
permit tcp any any 38.116.36.20 255.255.255.255 554
permit tcp any any 38.116.36.20 255.255.255.255 1755
permit udp any any 38.116.36.20 255.255.255.255 80
permit udp any any 38.116.36.20 255.255.255.255 554
permit udp any any 38.116.36.20 255.255.255.255 1755
permit udp any any 38.116.36.3 255.255.255.255 80
permit udp any any 38.116.36.3 255.255.255.255 554
permit udp any any 38.116.36.3 255.255.255.255 1755
permit tcp any any 38.116.36.3 255.255.255.255 80
permit tcp any any 38.116.36.3 255.255.255.255 554
permit tcp any any 38.116.36.3 255.255.255.255 1755
permit udp any any 38.116.36.4 255.255.255.255 80
permit udp any any 38.116.36.4 255.255.255.255 554
permit udp any any 38.116.36.4 255.255.255.255 1755
permit tcp any any 38.116.36.4 255.255.255.255 80
permit tcp any any 38.116.36.4 255.255.255.255 554
permit tcp any any 38.116.36.4 255.255.255.255 1755
permit udp any any 38.116.36.5 255.255.255.255 80
permit udp any any 38.116.36.5 255.255.255.255 554
permit udp any any 38.116.36.5 255.255.255.255 1755
permit tcp any any 38.116.36.5 255.255.255.255 80
permit tcp any any 38.116.36.5 255.255.255.255 554
permit tcp any any 38.116.36.5 255.255.255.255 1755
permit udp any any 38.116.36.6 255.255.255.255 80
permit udp any any 38.116.36.6 255.255.255.255 554
permit udp any any 38.116.36.6 255.255.255.255 1755
permit tcp any any 38.116.36.6 255.255.255.255 80
permit tcp any any 38.116.36.6 255.255.255.255 554
permit tcp any any 38.116.36.6 255.255.255.255 1755
permit udp any any 38.116.36.7 255.255.255.255 80
permit udp any any 38.116.36.7 255.255.255.255 554
permit udp any any 38.116.36.7 255.255.255.255 1755
permit tcp any any 38.116.36.7 255.255.255.255 80
permit tcp any any 38.116.36.7 255.255.255.255 554
permit tcp any any 38.116.36.7 255.255.255.255 1755
permit udp any any 38.116.36.8 255.255.255.255 80
permit udp any any 38.116.36.8 255.255.255.255 554
permit udp any any 38.116.36.8 255.255.255.255 1755
permit tcp any any 38.116.36.8 255.255.255.255 80
permit tcp any any 38.116.36.8 255.255.255.255 554
permit tcp any any 38.116.36.8 255.255.255.255 1755