1721 configuration question - please bear with me

Hello,,

I would like to extend the existing firewall configuration of a Cisco

1721 (IOS C1700 v. 12.3).

For the section:

! ip access-list extended Firewall-In

I would like to add the following entries, to open up ports on an external IP (which is NATed to a LAN IP) for a second mail server:

permit tcp any host 6x.6x.2x.3 eq www permit tcp any host 6x.6x.2x.3 eq 443 permit tcp any host 6x.6x.2x.3 eq smtp permit tcp any host 6x.6x.2x.3 eq 995

After logging in with SSH to the router, I enter:

router# config -t

Could you let me know step-by-step, exactly what should I enter to add and save the new configuration, please?

As you can tell, I am not a Cisco guy, please bear with me.

Thank you very much for your kind help.

Regards, Nick

Reply to
random.nick
Loading thread data ...

Hi Nick,

You may wish to investigate the Cisco Router SDM Wizard:

SDM provides smart wizards and advanced configuration support for LAN and WAN configurations, NAT, Stateful Firewall Policy, Intrusion Prevention, IPSec virtual private network (VPN), Easy VPN Client and Server configurations, Digital Certificates, and Quality of Service (QoS) Policy features.

SDM also offers a 1-click router lockdown and an innovative Security Auditing capability to check and recommend changes to router configuration based on ICSA Labs, and Cisco TAC recommendations.

formatting link
Cisco 1700 Tech Documentation:

formatting link
Sincerely,

Brad Reese

formatting link

Reply to
www.BradReese.Com

Nick, You really need to do some homework on your own first. While everyone on this group is extremely helpful, I've both requested and offered help, it's generally accepted that we're not here to do it for you. After all, most of us are in the business of doing this. Do a Google search and search the Cisco site for Access Control List, if its already configured as a firewall there must be at least one ACL. Good luck

Reply to
RC

Dear Brad,

Thank you so much to draw my attention to SDM!

I have installed it and it's an awesome tool, it does everything I always wanted to do with the router.

One of my favourite features is that it's not a "black box", I can check the commands for all actions, which makes it a great learning device.

Again, thank you very much!

Best Regards, Nick

formatting link
wrote:

formatting link

Reply to
random.nick

Hi RC,

Thank you for your response. I am sorry that I came across as a completely ignorant guy and I did not intend to insult here anybody, since I have also found that members of the list are very friendly and helpful.

I was in a rush while posting this message, at previous times I tried to "prove" better that I had put efforts before asking for help.

With Cisco it's not that simple to Google for quick solution, due to the huge amount of extensive documents, the complexity and unique nature of IOS itself. It's not enough to find the right command, syntax, it has to be in the right context. With daily exposure to Cisco this all makes sense and maybe even simple, but for occasional users, like myself, who just need to make some minor modifications once or twice a year, it's a bigger challenge than other OS or programming language "quick fixes". Even a trivial question that I posted.

Again, thank you for your help.

Regards,

RC wrote:

Reply to
random.nick

Cabling-Design.com Forums website is not affiliated with any of the manufacturers or service providers discussed here. All logos and trade names are the property of their respective owners.