08 January, 2014

Some Basic Cisco ACLs

#Permit HSRP Traffic
access-list 101 permit udp host 10.0.101.X host 224.0.0.2 eq 1985

#Filter DNS Traffic
access-list 101 permit udp 10.0.101.0 0.0.0.255 host 10.0.200.X eq 53
access-list 101 permit udp 10.0.101.0 0.0.0.255 host 8.8.8.8 eq 53
access-list 101 deny udp 10.0.101.0 0.0.0.255 any eq 53 log
access-list 101 deny tcp 10.0.101.0 0.0.0.255 any eq 53 log

#Permit DHCP Packets
access-list 101 permit udp host 0.0.0.0 eq bootpc host 255.255.255.255 eq bootps
access-list 101 permit udp host 0.0.0.0 eq bootpc any eq bootps (optional)
access-list 101 permit udp 10.0.101.0 0.0.0.255 eq bootpc any eq bootps

#Navegation HTTP and HTTPS Local WEBs
access-list 101 permit tcp 10.0.101.0 0.0.0.255 gt 1024 10.0.220.0 0.0.0.255 eq 80
access-list 101 permit tcp 10.0.101.0 0.0.0.255 gt 1024 10.0.220.0 0.0.0.255 eq 443

#Navegation Using Proxy
access-list 101 permit tcp 10.0.101.0 0.0.0.255 host 10.0.250.11 eq 8080

#Deny Access Between VLANs
access-list 101 deny ip 10.0.101.0 0.0.0.255 10.0.0.0 0.0.255.255 log

#Navegation HTTP and HTTPS
access-list 101 permit tcp 10.0.101.0 0.0.0.255 gt 1024 any eq 80
access-list 101 permit tcp 10.0.101.0 0.0.0.255 gt 1024 any eq 443

#Deny any and Log it
access-list 101 deny ip any any log