<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to create a Access list on core switch to bloxk all Internet Traffic &amp; allow some specific Internet Traffic in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/how-to-create-a-access-list-on-core-switch-to-bloxk-all-internet/m-p/2325974#M1050597</link>
    <description>&lt;P&gt;Hellp Everyone,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #fbfbde; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;I am trying to create a Access-List on my Core Switch, in which I want to allow few internet website &amp;amp; block the rest of them.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #fbfbde; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;I want to allow the whole Intranet but few intranet websites also needs access to the internet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #fbfbde; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;Can we create such Access-List with the above requirement.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #fbfbde; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;I tried to create the ACL on the switch but it blocks the whole internet access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #fbfbde; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;i want to do it for a subnet not for a specific IP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #fbfbde; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;Can someone help me in creating such access list.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #fbfbde; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;Thanks in Advance&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 12:57:57 GMT</pubDate>
    <dc:creator>vishwasjaiswal</dc:creator>
    <dc:date>2020-02-21T12:57:57Z</dc:date>
    <item>
      <title>How to create a Access list on core switch to bloxk all Internet Traffic &amp; allow some specific Internet Traffic</title>
      <link>https://community.cisco.com/t5/network-security/how-to-create-a-access-list-on-core-switch-to-bloxk-all-internet/m-p/2325974#M1050597</link>
      <description>&lt;P&gt;Hellp Everyone,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #fbfbde; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;I am trying to create a Access-List on my Core Switch, in which I want to allow few internet website &amp;amp; block the rest of them.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #fbfbde; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;I want to allow the whole Intranet but few intranet websites also needs access to the internet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #fbfbde; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;Can we create such Access-List with the above requirement.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #fbfbde; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;I tried to create the ACL on the switch but it blocks the whole internet access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #fbfbde; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;i want to do it for a subnet not for a specific IP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #fbfbde; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;Can someone help me in creating such access list.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #fbfbde; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;Thanks in Advance&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 12:57:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-create-a-access-list-on-core-switch-to-bloxk-all-internet/m-p/2325974#M1050597</guid>
      <dc:creator>vishwasjaiswal</dc:creator>
      <dc:date>2020-02-21T12:57:57Z</dc:date>
    </item>
    <item>
      <title>Re: How to create a Access list on core switch to bloxk all Inte</title>
      <link>https://community.cisco.com/t5/network-security/how-to-create-a-access-list-on-core-switch-to-bloxk-all-internet/m-p/2325975#M1050615</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The exact syntax depends on your subnets and how they connect to the Internet. If you can share a simple diagram that would be much more informative.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In general just remember that access-lists are parsed from the top down and as soon as a match is found, the processing stops. So you put the most specific rules at the top. also, once you add an access-list, there is an implicit "deny any any" at the end.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The best approach is to create some network object-groups and then refer to them in your access list. From your description, that would be something like three object-groups - one for the Intranet (Intranet), one for the allowed servers that can use Internet (allowed_servers), and a third for the permitted Internet sites (allowed_sites). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You would then use them as follows:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;ip access-list extended main_acl&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt; permit any object-group intranet any&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt; permit object-group allowed_servers object-group allowed_sites any&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;interface vlan &lt;VLAN id=""&gt;&lt;/VLAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt; ip access-group main_acl in&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;More details on the syntax and examples can be found here:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/docs/ios-xml/ios/sec_data_acl/configuration/15-2mt/sec-object-group-acl.html#GUID-BE5C124C-CCE0-423A-B147-96C33FA18C66" rel="nofollow"&gt;http://www.cisco.com/en/US/docs/ios-xml/ios/sec_data_acl/configuration/15-2mt/sec-object-group-acl.html#GUID-BE5C124C-CCE0-423A-B147-96C33FA18C66&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 18 Aug 2013 14:19:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-create-a-access-list-on-core-switch-to-bloxk-all-internet/m-p/2325975#M1050615</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2013-08-18T14:19:57Z</dc:date>
    </item>
  </channel>
</rss>

