You are on page 1of 3

ACL en HQ

interface FastEthernet0/0
description HQ LAN 1
ip address 10.1.50.1 255.255.255.0
ip access-group 101 in
duplex auto
speed auto
!
interface FastEthernet0/1
description HQ LAN 2
ip address 10.1.40.1 255.255.255.0
ip access-group 10 out
duplex auto
speed auto
!
interface Serial0/1/0
description Link to ISP
ip address 209.165.201.2 255.255.255.252
ip access-group FIREWALL in
-------------------------------------------------------------------------------------------------------------------
access-list 10 deny 10.1.10.0 0.0.0.255
access-list 10 permit any
access-list 101 deny tcp 10.1.50.0 0.0.0.63 host 10.1.80.16 eq www
access-list 101 permit ip any any
ip access-list extended FIREWALL
permit icmp any any echo-reply
permit tcp any any established
deny ip any any

ACL en B1
interface FastEthernet0/0
description B1 LAN 1
ip address 10.1.10.1 255.255.255.0
ip access-group 115 in
duplex auto
speed auto
---------------------------------------------------------------------------------------------------------------------
access-list 115 deny ip host 10.1.10.5 host 10.1.50.7
access-list 115 permit ip any any

ACL en B2
interface FastEthernet0/1
description B2 LAN 2
ip address 10.1.70.1 255.255.255.0
ip access-group NO_FTP in
duplex auto
speed auto
---------------------------------------------------------------------------------------------------------------------
ip access-list extended NO_FTP
deny tcp 10.1.70.0 0.0.0.255 host 10.1.10.2 eq ftp
permit ip any any

You might also like