Access-list og NAT table i cisco router
Hej der,Jeg har et lille spørgsmål, eller rettere en tese jeg gerne vil ha' be eller afkræftet.
I vores router har jeg en NAT tabel hvor flere porte er åbne:
Den ser således ud :
ip nat inside source static tcp 10.0.0.9 1720 interface FastEthernet0/0 1720
ip nat inside source static tcp 10.0.0.9 3230 interface FastEthernet0/0 3230
ip nat inside source static tcp 10.0.0.9 3231 interface FastEthernet0/0 3231
ip nat inside source static tcp 10.0.0.9 3232 interface FastEthernet0/0 3232
ip nat inside source static tcp 10.0.0.9 3233 interface FastEthernet0/0 3233
ip nat inside source static tcp 10.0.0.9 3234 interface FastEthernet0/0 3234
ip nat inside source static tcp 10.0.0.9 3235 interface FastEthernet0/0 3235
ip nat inside source static tcp 10.0.0.9 3236 interface FastEthernet0/0 3236
ip nat inside source static tcp 10.0.0.9 3237 interface FastEthernet0/0 3237
ip nat inside source static tcp 10.0.0.9 3238 interface FastEthernet0/0 3238
ip nat inside source static tcp 10.0.0.9 3239 interface FastEthernet0/0 3239
ip nat inside source static tcp 10.0.0.9 3240 interface FastEthernet0/0 3240
ip nat inside source static tcp 10.0.0.9 3241 interface FastEthernet0/0 3241
ip nat inside source static tcp 10.0.0.9 3242 interface FastEthernet0/0 3243
ip nat inside source static udp 10.0.0.9 3230 interface FastEthernet0/0 3230
ip nat inside source static udp 10.0.0.9 3231 interface FastEthernet0/0 3231
ip nat inside source static udp 10.0.0.9 3232 interface FastEthernet0/0 3232
ip nat inside source static udp 10.0.0.9 3233 interface FastEthernet0/0 3233
ip nat inside source static udp 10.0.0.9 3234 interface FastEthernet0/0 3234
ip nat inside source static udp 10.0.0.9 3235 interface FastEthernet0/0 3235
ip nat inside source static udp 10.0.0.9 3236 interface FastEthernet0/0 3236
ip nat inside source static udp 10.0.0.9 3237 interface FastEthernet0/0 3237
ip nat inside source static udp 10.0.0.9 3238 interface FastEthernet0/0 3238
ip nat inside source static udp 10.0.0.9 3239 interface FastEthernet0/0 3239
ip nat inside source static udp 10.0.0.9 3240 interface FastEthernet0/0 3240
ip nat inside source static udp 10.0.0.9 3241 interface FastEthernet0/0 3241
ip nat inside source static udp 10.0.0.9 3242 interface FastEthernet0/0 3242
ip nat inside source static udp 10.0.0.9 3243 interface FastEthernet0/0 3243
ip nat inside source static udp 10.0.0.9 3244 interface FastEthernet0/0 3244
ip nat inside source static udp 10.0.0.9 3245 interface FastEthernet0/0 3245
ip nat inside source static udp 10.0.0.9 3246 interface FastEthernet0/0 3246
ip nat inside source static udp 10.0.0.9 3247 interface FastEthernet0/0 3247
ip nat inside source static udp 10.0.0.9 3248 interface FastEthernet0/0 3248
ip nat inside source static udp 10.0.0.9 3249 interface FastEthernet0/0 3249
ip nat inside source static udp 10.0.0.9 3250 interface FastEthernet0/0 3250
ip nat inside source static udp 10.0.0.9 3251 interface FastEthernet0/0 3251
ip nat inside source static udp 10.0.0.9 3252 interface FastEthernet0/0 3252
ip nat inside source static udp 10.0.0.9 3253 interface FastEthernet0/0 3253
ip nat inside source static udp 10.0.0.9 3254 interface FastEthernet0/0 3254
ip nat inside source static udp 10.0.0.9 3255 interface FastEthernet0/0 3255
ip nat inside source static udp 10.0.0.9 3256 interface FastEthernet0/0 3256
ip nat inside source static udp 10.0.0.9 3257 interface FastEthernet0/0 3257
ip nat inside source static udp 10.0.0.9 3258 interface FastEthernet0/0 3258
ip nat inside source static udp 10.0.0.9 3259 interface FastEthernet0/0 3259
ip nat inside source static udp 10.0.0.9 3260 interface FastEthernet0/0 3260
ip nat inside source static udp 10.0.0.9 3261 interface FastEthernet0/0 3261
ip nat inside source static udp 10.0.0.9 3262 interface FastEthernet0/0 3262
ip nat inside source static udp 10.0.0.9 3263 interface FastEthernet0/0 3263
ip nat inside source static udp 10.0.0.9 3264 interface FastEthernet0/0 3264
ip nat inside source static udp 10.0.0.9 3265 interface FastEthernet0/0 3265
ip nat inside source static udp 10.0.0.9 3266 interface FastEthernet0/0 3266
ip nat inside source static udp 10.0.0.9 3267 interface FastEthernet0/0 3267
ip nat inside source static udp 10.0.0.9 3268 interface FastEthernet0/0 3268
ip nat inside source static udp 10.0.0.9 3269 interface FastEthernet0/0 3269
ip nat inside source static udp 10.0.0.9 3270 interface FastEthernet0/0 3270
ip nat inside source static udp 10.0.0.9 3271 interface FastEthernet0/0 3271
ip nat inside source static udp 10.0.0.9 3272 interface FastEthernet0/0 3272
ip nat inside source static udp 10.0.0.9 3273 interface FastEthernet0/0 3273
ip nat inside source static udp 10.0.0.9 3274 interface FastEthernet0/0 3274
ip nat inside source static udp 10.0.0.9 3275 interface FastEthernet0/0 3275
ip nat inside source static udp 10.0.0.9 3276 interface FastEthernet0/0 3276
ip nat inside source static udp 10.0.0.9 3277 interface FastEthernet0/0 3277
ip nat inside source static udp 10.0.0.9 3278 interface FastEthernet0/0 3278
ip nat inside source static udp 10.0.0.9 3279 interface FastEthernet0/0 3279
ip nat inside source static udp 10.0.0.9 3280 interface FastEthernet0/0 3280
ip nat inside source static udp 10.0.0.9 3281 interface FastEthernet0/0 3281
ip nat inside source static udp 10.0.0.9 3282 interface FastEthernet0/0 3282
ip nat inside source static udp 10.0.0.9 3283 interface FastEthernet0/0 3283
ip nat inside source static udp 10.0.0.9 3284 interface FastEthernet0/0 3284
ip nat inside source static udp 10.0.0.9 3285 interface FastEthernet0/0 3285
og det ser jo meget fint ud. Alle de porte jeg har brug for er åbne.
Men i min access-list er kun følgende åbne (outgoing)
access-list 101 permit tcp any host 85.86.87.88 eq 1720
access-list 101 permit tcp any host 85.86.87.88 eq 3230
access-list 101 permit tcp any host 85.86.87.88 eq 3231
access-list 101 permit udp any host 85.86.87.88 eq 3230
access-list 101 permit udp any host 85.86.87.88 eq 3231
access-list 101 permit udp any host 85.86.87.88 eq 3232
access-list 101 permit udp any host 85.86.87.88 eq 3233
access-list 101 permit udp any host 85.86.87.88 eq 3234
access-list 101 permit udp any host 85.86.87.88 eq 3235
mit spørgsmål er ganske enkelt:
Er det ikke sådan at de samme porte også skal permittes i access-list for at være gennemsigtig på de specifikke porte?
Og som tillæg:
Bør de også være permitted i access-list for indkommende trafik (102)?
Takker og bukker på forhånd :-)