Ik ben hier al een tijdje mee zoet, maar kom er niet uit.
we hebben hier een aantal vlan's waarbij vlan1 "bescherm" is tegen vlan 2
in principe mag er dus niemand van vlan 2 naar 1. nu is het zo dat er in vlan1 een webserver staat die ook benaderbaar moet zijn vanuit vlan 2. er moet dus een regel in die toegang toestaat de websever is 172.16.200.63.
iemand die mij even op weg kan helpen?
ip access-list extended "101"
10 permit ip 0.0.0.0 255.255.255.255 172.26.200.5 0.0.0.0
20 permit ip 0.0.0.0 255.255.255.255 172.26.200.20 0.0.0.0
21 permit tcp 0.0.0.0 255.255.255.255 172.16.200.63 0.0.0.0 eq 443
22 permit tcp 0.0.0.0 255.255.255.255 172.16.200.63 0.0.0.0 eq 80
23 permit ip 0.0.0.0 255.255.255.255 172.16.200.63 0.0.0.0
30 deny ip 0.0.0.0 255.255.255.255 172.26.0.0 0.0.255.255
40 deny ip 0.0.0.0 255.255.255.255 172.27.0.0 0.0.255.255
50 permit ip 0.0.0.0 255.255.255.255 0.0.0.0 255.255.255.255
60 permit icmp 0.0.0.0 255.255.255.255 172.26.200.5 0.0.0.0
70 permit icmp 0.0.0.0 255.255.255.255 172.26.200.20 0.0.0.0
80 deny icmp 0.0.0.0 255.255.255.255 172.26.0.0 0.0.255.255
90 deny icmp 0.0.0.0 255.255.255.255 172.27.0.0 0.0.255.255
100 permit icmp 0.0.0.0 255.255.255.255 0.0.0.0 255.255.255.255
exit
ip access-list extended "102"
10 permit ip 172.26.200.5 0.0.0.0 0.0.0.0 255.255.255.255
11 permit tcp 172.16.200.63 0.0.0.0 0.0.0.0 255.255.255.255 eq 443
20 permit ip 172.26.200.20 0.0.0.0 0.0.0.0 255.255.255.255
21 permit tcp 0.0.0.0 255.255.255.255 172.16.200.63 0.0.0.0 eq 443
22 permit tcp 0.0.0.0 255.255.255.255 172.16.200.63 0.0.0.0 eq 80
30 deny ip 0.0.0.0 255.255.255.255 172.16.0.0 0.0.255.255
40 deny ip 0.0.0.0 255.255.255.255 172.17.0.0 0.0.255.255
50 deny ip 0.0.0.0 255.255.255.255 172.27.0.0 0.0.255.255
60 permit ip 0.0.0.0 255.255.255.255 0.0.0.0 255.255.255.255
70 permit icmp 172.26.200.5 0.0.0.0 0.0.0.0 255.255.255.255
80 permit icmp 172.26.200.20 0.0.0.0 0.0.0.0 255.255.255.255
90 deny icmp 0.0.0.0 255.255.255.255 172.16.0.0 0.0.255.255
100 deny icmp 0.0.0.0 255.255.255.255 172.17.0.0 0.0.255.255
110 deny icmp 0.0.0.0 255.255.255.255 172.27.0.0 0.0.255.255
120 permit icmp 0.0.0.0 255.255.255.255 0.0.0.0 255.255.255.255
exit
vlan 1
name "vlan1"
untagged 9-12,20,22-24
ip helper-address 172.20.200.7
ip helper-address 172.20.200.9
ip address 172.16.175.1 255.255.0.0
tagged 5-8,Trk2
no untagged 13-15,17,19,21,Trk1
ip igmp
ip access-group "101" in
exit
vlan 2
name "vlan2"
untagged 13-14
ip helper-address 172.20.200.7
ip helper-address 172.20.200.9
ip address 172.26.175.1 255.255.0.0
tagged 5-8,23-24,Trk2
ip igmp
ip access-group "102" in
exit
we hebben hier een aantal vlan's waarbij vlan1 "bescherm" is tegen vlan 2
in principe mag er dus niemand van vlan 2 naar 1. nu is het zo dat er in vlan1 een webserver staat die ook benaderbaar moet zijn vanuit vlan 2. er moet dus een regel in die toegang toestaat de websever is 172.16.200.63.
iemand die mij even op weg kan helpen?
ip access-list extended "101"
10 permit ip 0.0.0.0 255.255.255.255 172.26.200.5 0.0.0.0
20 permit ip 0.0.0.0 255.255.255.255 172.26.200.20 0.0.0.0
21 permit tcp 0.0.0.0 255.255.255.255 172.16.200.63 0.0.0.0 eq 443
22 permit tcp 0.0.0.0 255.255.255.255 172.16.200.63 0.0.0.0 eq 80
23 permit ip 0.0.0.0 255.255.255.255 172.16.200.63 0.0.0.0
30 deny ip 0.0.0.0 255.255.255.255 172.26.0.0 0.0.255.255
40 deny ip 0.0.0.0 255.255.255.255 172.27.0.0 0.0.255.255
50 permit ip 0.0.0.0 255.255.255.255 0.0.0.0 255.255.255.255
60 permit icmp 0.0.0.0 255.255.255.255 172.26.200.5 0.0.0.0
70 permit icmp 0.0.0.0 255.255.255.255 172.26.200.20 0.0.0.0
80 deny icmp 0.0.0.0 255.255.255.255 172.26.0.0 0.0.255.255
90 deny icmp 0.0.0.0 255.255.255.255 172.27.0.0 0.0.255.255
100 permit icmp 0.0.0.0 255.255.255.255 0.0.0.0 255.255.255.255
exit
ip access-list extended "102"
10 permit ip 172.26.200.5 0.0.0.0 0.0.0.0 255.255.255.255
11 permit tcp 172.16.200.63 0.0.0.0 0.0.0.0 255.255.255.255 eq 443
20 permit ip 172.26.200.20 0.0.0.0 0.0.0.0 255.255.255.255
21 permit tcp 0.0.0.0 255.255.255.255 172.16.200.63 0.0.0.0 eq 443
22 permit tcp 0.0.0.0 255.255.255.255 172.16.200.63 0.0.0.0 eq 80
30 deny ip 0.0.0.0 255.255.255.255 172.16.0.0 0.0.255.255
40 deny ip 0.0.0.0 255.255.255.255 172.17.0.0 0.0.255.255
50 deny ip 0.0.0.0 255.255.255.255 172.27.0.0 0.0.255.255
60 permit ip 0.0.0.0 255.255.255.255 0.0.0.0 255.255.255.255
70 permit icmp 172.26.200.5 0.0.0.0 0.0.0.0 255.255.255.255
80 permit icmp 172.26.200.20 0.0.0.0 0.0.0.0 255.255.255.255
90 deny icmp 0.0.0.0 255.255.255.255 172.16.0.0 0.0.255.255
100 deny icmp 0.0.0.0 255.255.255.255 172.17.0.0 0.0.255.255
110 deny icmp 0.0.0.0 255.255.255.255 172.27.0.0 0.0.255.255
120 permit icmp 0.0.0.0 255.255.255.255 0.0.0.0 255.255.255.255
exit
vlan 1
name "vlan1"
untagged 9-12,20,22-24
ip helper-address 172.20.200.7
ip helper-address 172.20.200.9
ip address 172.16.175.1 255.255.0.0
tagged 5-8,Trk2
no untagged 13-15,17,19,21,Trk1
ip igmp
ip access-group "101" in
exit
vlan 2
name "vlan2"
untagged 13-14
ip helper-address 172.20.200.7
ip helper-address 172.20.200.9
ip address 172.26.175.1 255.255.0.0
tagged 5-8,23-24,Trk2
ip igmp
ip access-group "102" in
exit