Cisco Systems Firewall Config on 1700 IOS

Bookmark this page:  YahooMyWeb Yahoo!  Google Google  Windows Live Favorites Windows Live  del.icio.us del.icio.us  digg digg  Add to Netscape Netscape
Subject Author Date
Firewall Config on 1700 IOS CrimsonTide 09-09-05
Posted by CrimsonTide on September 9, 2005, 10:39 am
Please log in for more thread options
Hi,

I just added a WIC to our 1700 to provide a 2nd subnet to our office.

I would like to keep subnet 1 and subnet 2 from seeing each other.

Do I need to put another access list on the e0 interface that says,
basically, permit to the internet, but deny to 192.168.1.0?

Thanks



Router1721#
Router1721#sh run
Building configuration...

Current configuration : 1610 bytes
!
version 12.2
service timestamps debug datetime msec
service timestamps log datetime msec
service password-encryption
!
hostname Router1721
!
logging queue-limit 100
enable secret 5 WNZ.
enable password 7 0019
!
ip subnet-zero
!
!
no ip domain lookup
!
ip audit notify log
ip audit po max-events 100
!
!
!
!
crypto isakmp policy 1
encr 3des
hash md5
authentication pre-share
group 2
crypto isakmp key AbCdE123 address 62.5.175.10
!
!
crypto ipsec transform-set To_VPN esp-3des esp-md5-hmac
!
crypto map To_VPN 10 ipsec-isakmp
set peer 62.5.175.10
set transform-set To_VPN
match address 110
!
!
!
!
interface Ethernet0
ip address 10.1.1.1 255.255.255.0
ip nat inside
half-duplex
!
interface FastEthernet0
ip address 192.168.1.1 255.255.255.0
ip nat inside
speed auto
full-duplex
!
interface Serial0
bandwidth 832000
ip address 62.19.207.105 255.255.255.248
ip nat outside
no fair-queue
crypto map To_VPN
!

ip nat inside source route-map nonat interface Serial0 overload
ip classless
ip route 0.0.0.0 0.0.0.0 Serial0
no ip http server
no ip http secure-server
!
!
!
access-list 1 permit 192.168.1.0 0.0.0.255
access-list 110 permit ip 192.168.1.0 0.0.0.255 192.168.0.0 0.0.0.255
access-list 120 deny ip 192.168.1.0 0.0.0.255 192.168.0.0 0.0.255.255
access-list 120 permit ip 192.168.1.0 0.0.0.255 any
access-list 120 permit ip 10.1.1.0 0.0.0.255 any
!
route-map nonat permit 10
match ip address 120
!
!
line con 0
line aux 0
line vty 0 3
password 7 1D
login
line vty 4
password 7 035
login
!
end



Posted by RobO on September 10, 2005, 7:34 am
Please log in for more thread options
CrimsonTide wrote:
> Hi,
>
> I just added a WIC to our 1700 to provide a 2nd subnet to our office.
>
> I would like to keep subnet 1 and subnet 2 from seeing each other.
>
> Do I need to put another access list on the e0 interface that says,
> basically, permit to the internet, but deny to 192.168.1.0?
>
> Thanks

Hi,

I think the simplest solution would be like you say to add an
access-list to e0.

I am not sure if there are any other ways of doing it.
Something like this:

access-list xxx deny ip 10.1.1.0 0.0.0.255 192.168.1.1 0.0.0.255
access-list xxx permit ip 10.1.1.0 0.0.0.255 any

Apply the access-list inbound on e0.

You could also add an access-list to fa0 to deny traffic to the 10.
subnet to make it more concrete.

Rob

Similar ThreadsPosted
Firewall Config on 1700 IOS September 9, 2005, 10:39 am
Cisco 1700 Dual WAN Config January 8, 2006, 6:34 pm
Cisco 1700 Config not able to processing internal webmail script October 21, 2007, 8:31 pm
Cisco 1841 T1 & Firewall Config HELP!!!!!!!!! November 9, 2005, 3:45 pm
Q on router/firewall config with pptp for clients enabled January 27, 2007, 12:50 am
General internet router and PIX firewall config questions December 4, 2007, 4:20 pm
quick config for 2610 t-1 router to netgear firewall? February 6, 2009, 4:28 pm
initial config of 3560, set config, cant ping~~nv_done: unable to open "flash:/C:\new\config.new February 5, 2008, 11:39 pm
Increasing data transfer on a firewall to firewall vpn connection June 14, 2005, 5:33 pm
Cisco 1700 July 27, 2006, 9:24 pm
cisco 1700 February 6, 2007, 11:23 am
Cisco 1700 and DNS cache July 18, 2005, 8:35 pm
crypto map problem on 1700 September 6, 2005, 3:17 pm
Cisco 1700 Problems November 17, 2005, 9:41 am
Cisco 1700 Router July 25, 2008, 8:00 am
Residential Cabling Guide

Home Cabling Guide

Finally, an instantly downloadable book that saves you thousands in home improvement dollars! Enjoy living in 21st century technology-advanced home while increasing its selling value and competitive advantage on the real estate market. Whether your cabling is for home office or high-tech leisure, you can wire your home yourself or learn "wirish" to speak with your cabling contractors in their language!

Learn More