<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Need help for access list problem in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/need-help-for-access-list-problem/m-p/2333135#M343360</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Does the TMG server know how to get to the internet? Has it got a default route pointing towards the router ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Alain&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Don't forget to rate helpful posts.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 09 Sep 2013 14:00:39 GMT</pubDate>
    <dc:creator>cadet alain</dc:creator>
    <dc:date>2013-09-09T14:00:39Z</dc:date>
    <item>
      <title>Need help for access list problem</title>
      <link>https://community.cisco.com/t5/network-security/need-help-for-access-list-problem/m-p/2333130#M343355</link>
      <description>&lt;P&gt;Cisco 2901 ISR &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I need help for my configuration.... although it is working fine but it is not secured cause everybody can access the internet&lt;/P&gt;&lt;P&gt;I want to deny this IP range and permit only TMG server to have internet connection. My DHCP server is the 4500 switch.&lt;/P&gt;&lt;P&gt;Anybody can help?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; DENY&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.25.0.1 – 10.25.0.255&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.25.1.1 – 10.25.1.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Permit only 1 host for Internet&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.25.7.136&amp;nbsp; 255.255.255.192 ------ TMG Server&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Using access-list.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;( Current configuration&amp;nbsp; )&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object-group network IP&lt;/P&gt;&lt;P&gt;description Block_IP&lt;/P&gt;&lt;P&gt;range 10.25.0.2 10.25.0.255&lt;/P&gt;&lt;P&gt;range 10.25.1.2 10.25.1.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/0&lt;/P&gt;&lt;P&gt;ip address 192.168.2.3 255.255.255.0&lt;/P&gt;&lt;P&gt;ip nat inside&lt;/P&gt;&lt;P&gt;ip virtual-reassembly in max-fragments 64 max-reassemblies 256&lt;/P&gt;&lt;P&gt;duplex auto&lt;/P&gt;&lt;P&gt;speed auto&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/1&lt;/P&gt;&lt;P&gt;description ### ADSL WAN Interface ###&lt;/P&gt;&lt;P&gt;no ip address&lt;/P&gt;&lt;P&gt;pppoe enable group global&lt;/P&gt;&lt;P&gt;pppoe-client dial-pool-number 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface ATM0/0/0&lt;/P&gt;&lt;P&gt;no ip address&lt;/P&gt;&lt;P&gt;no atm ilmi-keepalive&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Dialer1&lt;/P&gt;&lt;P&gt;description ### ADSL WAN Dialer ###&lt;/P&gt;&lt;P&gt;ip address negotiated&lt;/P&gt;&lt;P&gt;ip mtu 1492&lt;/P&gt;&lt;P&gt;ip nat outside&lt;/P&gt;&lt;P&gt;no ip virtual-reassembly in&lt;/P&gt;&lt;P&gt;encapsulation ppp&lt;/P&gt;&lt;P&gt;dialer pool 1&lt;/P&gt;&lt;P&gt;dialer-group 1&lt;/P&gt;&lt;P&gt;ppp authentication pap callin&lt;/P&gt;&lt;P&gt;ppp pap sent-username xxxxxxx password 7 xxxxxxxxx&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip nat inside source list 101 interface Dialer1 overload&lt;/P&gt;&lt;P&gt;ip route 0.0.0.0 0.0.0.0 Dialer1&lt;/P&gt;&lt;P&gt;ip route 10.25.0.0 255.255.0.0 192.168.2.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list 101 permit ip 10.25.0.0 0.0.255.255 any&lt;/P&gt;&lt;P&gt;access-list 105 deny&amp;nbsp;&amp;nbsp; ip object-group IP any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14pt;"&gt;From the 4500 Catalyst switch&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;( Current Configuration )&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/48&lt;/P&gt;&lt;P&gt;no switchport&lt;/P&gt;&lt;P&gt;ip address 192.168.2.1 255.255.255.0&lt;SPAN id="mce_marker"&gt; &lt;/SPAN&gt;interface GigabitEthernet2/42&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip route 0.0.0.0 0.0.0.0 192.168.2.3&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 02:35:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-help-for-access-list-problem/m-p/2333130#M343355</guid>
      <dc:creator>joel.palen</dc:creator>
      <dc:date>2019-03-12T02:35:21Z</dc:date>
    </item>
    <item>
      <title>Need help for access list problem</title>
      <link>https://community.cisco.com/t5/network-security/need-help-for-access-list-problem/m-p/2333131#M343356</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;ip access-list extended 101&lt;/P&gt;&lt;P&gt;5 permit ip host 10.25.7.136 any&lt;/P&gt;&lt;P&gt;no 10&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This way you'll only NAT this host an not the others so they won't be able to get to the Internet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Alain&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Alain&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Don't forget to rate helpful posts.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 08 Sep 2013 10:42:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-help-for-access-list-problem/m-p/2333131#M343356</guid>
      <dc:creator>cadet alain</dc:creator>
      <dc:date>2013-09-08T10:42:35Z</dc:date>
    </item>
    <item>
      <title>Re: Need help for access list problem</title>
      <link>https://community.cisco.com/t5/network-security/need-help-for-access-list-problem/m-p/2333132#M343357</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I already use this command before, but it didn't work. The internet is disconnected.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 08 Sep 2013 11:09:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-help-for-access-list-problem/m-p/2333132#M343357</guid>
      <dc:creator>joel.palen</dc:creator>
      <dc:date>2013-09-08T11:09:21Z</dc:date>
    </item>
    <item>
      <title>Need help for access list problem</title>
      <link>https://community.cisco.com/t5/network-security/need-help-for-access-list-problem/m-p/2333133#M343358</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;you mean other hosts can't get to Internet or this host can't ping 8.8.8.8 ?&lt;/P&gt;&lt;P&gt;Just make sure your clients are configured to use the proxy to get to internet and try to ping 8.8.8.8 from one of these clients and look&amp;nbsp; at the NAT table with sh ip nat translation on the router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Alain&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Don't forget to rate helpful posts.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Sep 2013 08:26:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-help-for-access-list-problem/m-p/2333133#M343358</guid>
      <dc:creator>cadet alain</dc:creator>
      <dc:date>2013-09-09T08:26:13Z</dc:date>
    </item>
    <item>
      <title>Need help for access list problem</title>
      <link>https://community.cisco.com/t5/network-security/need-help-for-access-list-problem/m-p/2333134#M343359</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Host will can't get internet connection &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I remove this configuration......&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; access-list 101 permit ip 10.25.0.0 0.0.255.255 any&lt;/P&gt;&lt;P&gt;and change the configuration ....&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ip access-list extended 101&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5 permit ip host 10.25.7.136 any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In this case I will allow only host 10.25.7.136 but it isn't work.&lt;/P&gt;&lt;P&gt;No internet connection from the TMG Server.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Sep 2013 10:39:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-help-for-access-list-problem/m-p/2333134#M343359</guid>
      <dc:creator>joel.palen</dc:creator>
      <dc:date>2013-09-09T10:39:12Z</dc:date>
    </item>
    <item>
      <title>Need help for access list problem</title>
      <link>https://community.cisco.com/t5/network-security/need-help-for-access-list-problem/m-p/2333135#M343360</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Does the TMG server know how to get to the internet? Has it got a default route pointing towards the router ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Alain&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Don't forget to rate helpful posts.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Sep 2013 14:00:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-help-for-access-list-problem/m-p/2333135#M343360</guid>
      <dc:creator>cadet alain</dc:creator>
      <dc:date>2013-09-09T14:00:39Z</dc:date>
    </item>
    <item>
      <title>Need help for access list problem</title>
      <link>https://community.cisco.com/t5/network-security/need-help-for-access-list-problem/m-p/2333136#M343361</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;From the 4500 Catalyst switch&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;( Current Configuration )&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/48&lt;/P&gt;&lt;P&gt;no switchport&lt;/P&gt;&lt;P&gt;ip address 192.168.2.1 255.255.255.0 interface GigabitEthernet2/42&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip route 0.0.0.0 0.0.0.0 192.168.2.3&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TMG server&lt;/P&gt;&lt;P&gt;external lan 10.25.7.136 255.255.255.192&lt;/P&gt;&lt;P&gt;internal lan 10.25.51.10 255.255.255.0&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Sep 2013 16:33:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-help-for-access-list-problem/m-p/2333136#M343361</guid>
      <dc:creator>joel.palen</dc:creator>
      <dc:date>2013-09-09T16:33:29Z</dc:date>
    </item>
  </channel>
</rss>

