Acls In A Small Networked Office - Cisco Catalyst 3750-X Software Configuration Manual

Hide thumbs Also See for Catalyst 3750-X:
Table of Contents

Advertisement

Configuring IPv4 ACLs

ACLs in a Small Networked Office

Figure 37-3
containing benefits and other information that all employees can access, and routed Port 1 connected to
Server B, containing confidential payroll data. All users can access Server A, but Server B has restricted
access.
Use router ACLs to do this in one of two ways:
Figure 37-3
Human Resources
172.20.128.0-31
This example uses a standard ACL to filter traffic coming into Server B from a port, permitting traffic
only from Accounting's source addresses 172.20.128.64 to 172.20.128.95. The ACL is applied to traffic
coming out of routed Port 1 from the specified source address.
Switch(config)# access-list 6 permit 172.20.128.64 0.0.0.31
Switch(config)# end
Switch# show access-lists
Standard IP access list 6
Switch(config)# interface gigabitethernet1/0/1
Switch(config-if)# ip access-group 6 out
This example uses an extended ACL to filter traffic coming from Server B into a port, permitting traffic
from any source address (in this case Server B) to only the Accounting destination addresses
172.20.128.64 to 172.20.128.95. The ACL is applied to traffic going into routed Port 1, permitting it to
go only to the specified destination addresses. Note that with extended ACLs, you must enter the
protocol (IP) before the source and destination information.
Switch(config)# access-list 106 permit ip any 172.20.128.64 0.0.0.31
Switch(config)# end
Switch# show access-lists
Catalyst 3750-X and 3560-X Switch Software Configuration Guide
37-24
shows a small networked office environment with routed Port 2 connected to Server A,
Create a standard ACL, and filter traffic coming to the server from Port 1.
Create an extended ACL, and filter traffic coming from the server into Port 1.
Using Router ACLs to Control Traffic
Server A
Benefits
Port 2
10 permit 172.20.128.64, wildcard bits 0.0.0.31
Chapter 37
Server B
Payroll
Port 1
Accounting
172.20.128.64-95
Configuring Network Security with ACLs
OL-21521-01

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Catalyst 3560-x

Table of Contents