1. Computer problem? Tech Support Guy is completely free -- paid for by advertisers and donations. Click here to join today! If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

Cisco IOS Access List Help

Discussion in 'Networking' started by Doug Vitale, Feb 6, 2007.

Thread Status:
Not open for further replies.
  1. Doug Vitale

    Doug Vitale Thread Starter

    Joined:
    Jan 27, 2005
    Messages:
    148
    Would any Cisco experts be able to lend a hand with the following ACL requirements that I need to implement on a Cisco router at work?

    1. Block all inbound ICMP messages with the exception of Echo Reply (type 0), and Time Exceeded (type 11). ICMP message number 3, code 4, are permitted inbound with the following exception: Must be denied from external access gateway (AG) addresses, otherwise permitted.

    2. Also block outbound ICMP traffic message types except Echo Request (type 8), Parameter Problem (type 12), and Source Quench (type 4) Destination Unreachable - Fragmentation Needed and Don't Fragment was Set (type3, code 4).

    3. Also block all inbound traceroutes to prevent network discovery by unauthorized users.

    Thanks for any help!
     
  2. O111111O

    O111111O

    Joined:
    Aug 26, 2005
    Messages:
    894
    Assuming this is a router. Also, "blocking traceroute" is very ambiguous. It's close enough, a better way would be some reflexive ACL's, but this is assuming you're running 12.0x.

    int x/x
    ip access-group foo1 inbound
    ip access-group foo2 outbound
    !
    ip access-list extended foo1
    permit icmp any any echo reply
    permit icmp any any time exceeded
    deny icmp host x.x.x.x host y.y.y.y Destination Unreachable
    deny icmp host x.x.x.x host y.y.y.y Source Quench
    permit icmp any any Unreachable
    permit icmp any any Source Quench
    deny icmp any any log-input
    permit ip any any
    !
    ip access-list extended foo2
    permit icmp any any Echo Request
    permit icmp any any Parameter Problem
    permit icmp any any Source Quench
    permit icmp any any Unreachable
    deny icmp any any log-input
    permit ip any any
     
As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 733,556 other people just like you!

Loading...
Thread Status:
Not open for further replies.

Short URL to this thread: https://techguy.org/541699

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice