<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ACL in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acl/m-p/4071988#M559847</link>
    <description>Thank you, sir.&lt;BR /&gt;&lt;BR /&gt;It works well.&lt;BR /&gt;Does ACL execute the access-list in order?&lt;BR /&gt;It seems everything after "permit ip any any" will be ignore, isn`t it? (I still can access the ftp server.)&lt;BR /&gt;!&lt;BR /&gt;ip access-group 101 out&lt;BR /&gt;access-list 101 deny tcp 192.168.2.0 0.0.0.255 host 192.168.1.3 eq www&lt;BR /&gt;access-list 101 permit ip any any&lt;BR /&gt;access-list 101 deny tcp 192.168.3.0 0.0.0.255 host 192.168.1.4 eq ftp&lt;BR /&gt;!</description>
    <pubDate>Thu, 23 Apr 2020 03:14:24 GMT</pubDate>
    <dc:creator>will75136</dc:creator>
    <dc:date>2020-04-23T03:14:24Z</dc:date>
    <item>
      <title>ACL</title>
      <link>https://community.cisco.com/t5/network-access-control/acl/m-p/4071878#M559841</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="000.PNG" style="width: 739px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/72613i5573143052CBC5D2/image-size/large?v=v2&amp;amp;px=999" role="button" title="000.PNG" alt="000.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="3333.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/72614i7F77C2885449FFE2/image-size/large?v=v2&amp;amp;px=999" role="button" title="3333.PNG" alt="3333.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Hello experts, I have a question about ACL.&lt;/P&gt;&lt;P&gt;I have configured the first requirement like below on both R1 and R2.&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;access-list 101 deny tcp 192.168.2.0 0.0.0.255 host 192.168.1.3 eq www&lt;/P&gt;&lt;P&gt;!&amp;nbsp;&lt;/P&gt;&lt;P&gt;Though it works, I found that my PC in 192.168.3.0 network could not ping 192.168.1.0 network either.&lt;/P&gt;&lt;P&gt;Is there something I miss?&lt;/P&gt;</description>
      <pubDate>Wed, 22 Apr 2020 23:16:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acl/m-p/4071878#M559841</guid>
      <dc:creator>will75136</dc:creator>
      <dc:date>2020-04-22T23:16:33Z</dc:date>
    </item>
    <item>
      <title>Re: ACL</title>
      <link>https://community.cisco.com/t5/network-access-control/acl/m-p/4071888#M559843</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;do you have permit ip any any ?&lt;/P&gt;&lt;P&gt;each ACL has impicit &lt;U&gt;deny&lt;/U&gt; at the end of ACL; Such entry is &lt;U&gt;not visible&lt;/U&gt; normally. &amp;nbsp; therefore, you need permit any Or &lt;EM&gt;permit ip any any&lt;/EM&gt; Or specific network/host.&amp;nbsp; i,e permit&lt;EM&gt; icmp any&lt;/EM&gt; &lt;EM&gt;any&lt;/EM&gt; to ping , in your example, you may see &lt;EM&gt;access-list 101 deny ip any any&lt;/EM&gt; as last entry.&lt;/P&gt;&lt;P&gt;if you want to ping or allow other traffic, add &lt;EM&gt;access-list 101 permit ip any any&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards, ML&lt;BR /&gt;**Please Rate All Helpful Responses **&lt;/P&gt;</description>
      <pubDate>Wed, 22 Apr 2020 23:57:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acl/m-p/4071888#M559843</guid>
      <dc:creator>Martin L</dc:creator>
      <dc:date>2020-04-22T23:57:18Z</dc:date>
    </item>
    <item>
      <title>Re: ACL</title>
      <link>https://community.cisco.com/t5/network-access-control/acl/m-p/4071988#M559847</link>
      <description>Thank you, sir.&lt;BR /&gt;&lt;BR /&gt;It works well.&lt;BR /&gt;Does ACL execute the access-list in order?&lt;BR /&gt;It seems everything after "permit ip any any" will be ignore, isn`t it? (I still can access the ftp server.)&lt;BR /&gt;!&lt;BR /&gt;ip access-group 101 out&lt;BR /&gt;access-list 101 deny tcp 192.168.2.0 0.0.0.255 host 192.168.1.3 eq www&lt;BR /&gt;access-list 101 permit ip any any&lt;BR /&gt;access-list 101 deny tcp 192.168.3.0 0.0.0.255 host 192.168.1.4 eq ftp&lt;BR /&gt;!</description>
      <pubDate>Thu, 23 Apr 2020 03:14:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acl/m-p/4071988#M559847</guid>
      <dc:creator>will75136</dc:creator>
      <dc:date>2020-04-23T03:14:24Z</dc:date>
    </item>
    <item>
      <title>Re: ACL</title>
      <link>https://community.cisco.com/t5/network-access-control/acl/m-p/4072010#M559849</link>
      <description>&lt;BR /&gt;Yes, ACL order is from top to the bottom but it can stop once the match is found. In your case, you have 3 lines, line 3 is never read because line 2 will match all traffic (everything). router will never get to line 3. you have to re-arrange order.</description>
      <pubDate>Thu, 23 Apr 2020 04:17:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acl/m-p/4072010#M559849</guid>
      <dc:creator>Martin L</dc:creator>
      <dc:date>2020-04-23T04:17:05Z</dc:date>
    </item>
  </channel>
</rss>

