Access-list på Cisco 1710
Jeg har en VPN-opstilling mellem 3 Cisco 1710'ere, opstillingen virker fint så længe at der ikke er en firewall-access list på yder-interface'et.Når jeg smidder nedenstående ACL på ydersiden stopper alting i midlertid med at virke (ip access-group 150 in).
Af en eller anden uforklarlig grund, matcher alle pakker kun den allersidste regel (deny ip any any).
Ikke en gang en ping får lov til at passere i min tunnel...
access-list 150 permit icmp any any
access-list 150 permit esp any host xxx.xxxx.164.170
access-list 150 permit gre any host xxx.xxx.164.170
access-list 150 permit ahp any host xxx.xxx.164.170
access-list 150 permit udp any eq isakmp host xxx.xxx.164.170 eq isakmp
access-list 150 permit ip 192.168.10.0 0.0.0.255 192.168.13.0 0.0.0.255
access-list 150 permit ip 192.168.99.0 0.0.0.255 192.168.13.0 0.0.0.255
access-list 150 permit ip 192.168.12.0 0.0.0.255 192.168.13.0 0.0.0.255
access-list 150 permit tcp host xx.78.84.60 eq smtp any
access-list 150 permit ip host xx.78.84.60 xxx.xxx.164.0 255.255.255.128
access-list 150 permit ip host xx.78.84.60 host xxx.xxx.92.129
access-list 150 permit ip host xx.78.84.60 host xxx.xxx.92.130
access-list 150 permit ip 192.168.10.0 0.0.0.255 192.168.13.0 0.0.0.255
access-list 150 permit ip 192.168.99.0 0.0.0.255 192.168.13.0 0.0.0.255
access-list 150 permit ip 192.168.12.0 0.0.0.255 192.168.13.0 0.0.0.255
access-list 150 deny ip any any
