cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements

492
Views
0
Helpful
3
Replies
Highlighted
Beginner

Need help with ACL src/dest problem

I have a working ACL. It is applied inbound on the switch port with a server attached. However, the logic is confusing me, as if I switch src/dest around, it no longer works.

 

Setup:

3650 Switch, server on port g1/0/7. Switch trunked to a pair of 9k's in VPC mode

NTP server is 10.0.0.2

NTP client is 192.168.2.1

192.168.1.0 is a management network

ACL applied as so: ip access-group NTP_Working in on g1/0/7

 

 

ACL working:

ip access-list extended NTP_Working
permit udp host 10.0.0.2 eq ntp host 192.168.2.1
permit tcp host 10.0.0.2 eq www 192.168.1.0 0.0.0.255
permit tcp host 10.0.0.2 eq 443 192.168.1.0 0.0.0.255
permit icmp host 10.0.0.2 192.168.1.0 0.0.0.255 echo-reply

 

ACL Not working (just flipped source/dest):

ip access-list extended NTP_Not_Working
permit udp host 192.168.2.1 eq ntp host 192.168.2.1
permit tcp 192.168.1.0 0.0.0.255 eq www host 10.0.0.2
permit tcp 192.168.1.0 0.0.0.255 host 10.0.0.2 eq 443
permit icmp 192.168.1.0 0.0.0.255 host 10.0.0.2 echo-reply

 

All my logic is allow xx from source to destination. But taht is not working here.

Everyone's tags (1)
3 REPLIES 3
Highlighted
VIP Advisor

Re: Need help with ACL src/dest problem

you are definitely using it correct in source/destination order of ACE:

 

https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst3650/software/release/3se/security/configuration_guide/b_sec_3se_3650_cg/b_sec_3se_3650_cg_chapter_01010.html#concept_339DA61A054C4243B014617049EF5C09

 

is it just NTP that beaks or all the other traffic in the ACL as well?

 

 

Please remember to rate useful posts, by clicking on the stars below.

Highlighted
Beginner

Re: Need help with ACL src/dest problem

All traffic listed breaks, ie: www access and pings. 

 

Which ACL do you say looks good, the one labeled working or not working?

 

Thanks!

Highlighted
VIP Advisor

Re: Need help with ACL src/dest problem

you are definitley using it correct in source/destination in your ACE's:

 

 

https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst3650/software/release/3se/security/configuration_guide/b_sec_3se_3650_cg/b_sec_3se_3650_cg_chapter_01010.html#concept_339DA61A054C4243B014617049EF5C09

 

is it just NTP thta breaks or other traffic in the ACL as well?

Please remember to rate useful posts, by clicking on the stars below.

Everyone's tags (1)