Access-list på cisco 806.
Hej.Jeg kan bare ikke få min access-liste til at virke. Hver gang jeg enable den mit E1 interface (ip access-group 101 in), blockere den alt trafik. Hvordan kan dette værre?
Den er sat op i webpseed.
!
version 12.2
no parser cache
no service single-slot-reload-enable
no service pad
service timestamps debug uptime
service timestamps log uptime
service password-encryption
!
hostname Gateway
!
logging rate-limit console 10 except errors
enable secret xxxxxxxxxxxxxxxxxxxxxxxx.
!
username default privilege 15 password 7 xxxxxxxxxxxxxxxx
ip subnet-zero
no ip domain-lookup
ip name-server 194.239.10.41
ip name-server 194.239.134.83
ip dhcp excluded-address 10.10.10.1
ip dhcp excluded-address 10.10.10.2
ip dhcp excluded-address 10.10.10.3
ip dhcp excluded-address 10.10.10.4
ip dhcp excluded-address 10.10.10.5
!
ip dhcp pool Klienter
import all
network 10.10.10.0 255.255.255.0
default-router 10.10.10.1
dns-server 194.239.10.41 194.239.134.83
lease 14
!
no ip dhcp-client network-discovery
lcp max-session-starts 0
!
!
!
interface Ethernet0
description Interface til LAN
ip address 10.10.10.1 255.255.255.0
ip nat inside
!
interface Ethernet1
description Interface til Internet
mac-address 000b.6a40.1a53
ip address dhcp
ip nat outside
no ip route-cache
no ip mroute-cache
!
ip nat inside source list 102 interface Ethernet1 overload
ip classless
ip route 0.0.0.0 0.0.0.0 Ethernet1
ip http server
!
access-list 101 permit tcp any any eq www
access-list 101 permit tcp any any eq 443
access-list 101 permit tcp any any eq domain
access-list 101 permit udp any any eq domain
access-list 101 permit udp any any eq bootps
access-list 101 permit udp any any eq bootpc
access-list 101 deny ip any any log
access-list 102 permit ip 10.10.10.0 0.0.0.255 any
!
line con 0
stopbits 1
line vty 0
password 7 xxxxxxxxxxx
login
line vty 1 4
login
!
scheduler max-task-time 5000
end
Gateway#