07-12-2007 06:13 PM - edited 03-03-2019 05:50 PM
Hi,
I do understand what is access-list and why should i use it but i'm not sure about ip access-group on the interface to WAN.
In my case i have access-list on 1841 router along with relevant ip access-group on the wan interface. If i need to add additional access-list for example to allow traffic on different tunnel i have to create access-list but i can't add another ip access-group on the interface .
what should I do ?
hope my question is clear
Thank you
Solved! Go to Solution.
07-12-2007 06:39 PM
Barry
Yes, you just keep adding lines. Be careful though as you need to be aware that once a match is made in the access-list no further processing is done so you need to make sure the order of lines in your access-list allows or denies traffic in the right order.
Jon
07-12-2007 06:17 PM
Hi Barry
Yes you can only apply one access-list inbound and one outbound. I'm a little confued by the question. If you are filtering on your WAN interface just add the additional lines to your exiting access-list.
Or have i missed something ?
Jon
07-12-2007 06:28 PM
Hi Jon,
So basically you are saying that i should keep adding access-list's to same number as it appears under the interface
Thanks
07-12-2007 06:39 PM
Barry
Yes, you just keep adding lines. Be careful though as you need to be aware that once a match is made in the access-list no further processing is done so you need to make sure the order of lines in your access-list allows or denies traffic in the right order.
Jon
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide