09-10-2019 06:50 AM
Hi,
We have the following on a Cisco 2901:
Current configuration : 1999 bytes ! version 15.4 service timestamps debug datetime msec service timestamps log datetime msec no service password-encryption ! hostname Sky-GW01 ! boot-start-marker boot-end-marker ! ! enable secret 5 xxxxxxxxxxxxxxxxxxxxxxx enable password xxxxxxxxx ! aaa new-model ! ! aaa authentication login default none aaa authentication login VTY enable ! ! ! ! ! aaa session-id common clock timezone GMT 1 0 clock summer-time GMT recurring 1 Sun Apr 3:00 last Sun Oct 3:00 ! ! ! ! ! ! ! ! ! ! ! ! ! ! ip domain name domain.no ip name-server 8.8.8.8 ip name-server 8.4.4.8 ip cef no ipv6 cef multilink bundle-name authenticated ! ! cts logging verbose ! ! license udi pid CISCO2901/K9 sn FCZ1927C25G ! ! ! redundancy ! ! ip ssh authentication-retries 2 ip ssh version 2 ip ssh pubkey-chain username admin ! ! ! ! interface Embedded-Service-Engine0/0 no ip address shutdown ! interface GigabitEthernet0/0 description # Linknet # ip address 1.1.1.138 255.255.255.248 duplex auto speed auto no mop enabled ! interface GigabitEthernet0/1 description # mydesc # no ip address duplex auto speed auto ! interface GigabitEthernet0/1.10 encapsulation dot1Q 10 ip address 2.2.2.193 255.255.255.192 ! interface GigabitEthernet0/1.50 encapsulation dot1Q 50 ip address 2.2.2.129 255.255.255.192 secondary ip address 2.2.2.1 255.255.255.128 ! ip forward-protocol nd ! no ip http server no ip http secure-server ! ip route 0.0.0.0 0.0.0.0 3.3.3.3 ! ip access-list standard SSH permit 2.2.2.0 0.0.0.255 ! ! ! snmp-server community public RO snmp-server community private RW ! ! ! control-plane ! ! ! line con 0 privilege level 15 line aux 0 line 2 no activation-character no exec transport preferred none transport output pad telnet rlogin lapb-ta mop udptn v120 ssh stopbits 1 line vty 0 4 access-class SSH in privilege level 15 logging synchronous login authentication VTY transport input ssh ! scheduler allocate 20000 1000 ! end
-------
We want to block all incoming and outgoing traffic to both interfaces, interface GigabitEthernet0/1.10 and GigabitEthernet0/1.50.
In addition we want to allow for ports 3389, 60123 and ping. We also want to allow all traffic to and from both the interfaces internally.
How would we set this up in an easy way? (Ip's are not real, just replaced with 1s and 2s)
Thank you :)
09-10-2019 04:24 PM
Hi,
You need to clarify your requirements a bit.
Do you want 0/1.10 and 0/1.50 to be able to talk to each other but should not be able to talk to 0/0 except on ports 3389, 60123 and ping?
Thanks
John
09-11-2019 02:40 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide