 




<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Extended ACL</title>
	<atom:link href="http://itknowledgeexchange.techtarget.com/itanswers/extended-acl/feed/" rel="self" type="application/rss+xml" />
	<link>http://itknowledgeexchange.techtarget.com/itanswers/extended-acl/</link>
	<description></description>
	<lastBuildDate>Sun, 19 May 2013 03:14:28 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
	<item>
		<title>By: normc62</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/extended-acl/#comment-85453</link>
		<dc:creator>normc62</dc:creator>
		<pubDate>Thu, 16 Dec 2010 04:13:42 +0000</pubDate>
		<guid isPermaLink="false">#comment-85453</guid>
		<description><![CDATA[Hi Melanie,

Actually, it&#039;s the exact same problem that IFOY is having. In fact, I created my ACL in the exact same manner before coming here to see if someone had a solution [&quot;great minds think alike&quot;?]. I have to submit my assignment in the next day or two, so I figure I&#039;m going to end up with a 470/471 and I&#039;ll simply poke at it later and see if I can figure out where I/we went wrong.]]></description>
		<content:encoded><![CDATA[<p>Hi Melanie,</p>
<p>Actually, it&#8217;s the exact same problem that IFOY is having. In fact, I created my ACL in the exact same manner before coming here to see if someone had a solution ["great minds think alike"?]. I have to submit my assignment in the next day or two, so I figure I&#8217;m going to end up with a 470/471 and I&#8217;ll simply poke at it later and see if I can figure out where I/we went wrong.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: melanieyarbrough</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/extended-acl/#comment-85271</link>
		<dc:creator>melanieyarbrough</dc:creator>
		<pubDate>Mon, 13 Dec 2010 15:13:58 +0000</pubDate>
		<guid isPermaLink="false">#comment-85271</guid>
		<description><![CDATA[Hi Normc62,

If you &lt;a href=&quot;http://itknowledgeexchange.techtarget.com/itanswers/ask_question/&quot;&gt;open a new thread&lt;/a&gt; for your question, it might get more attention and possibly an answer this time! Best of luck. 

Melanie]]></description>
		<content:encoded><![CDATA[<p>Hi Normc62,</p>
<p>If you <a href="http://itknowledgeexchange.techtarget.com/itanswers/ask_question/">open a new thread</a> for your question, it might get more attention and possibly an answer this time! Best of luck. </p>
<p>Melanie</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: normc62</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/extended-acl/#comment-85202</link>
		<dc:creator>normc62</dc:creator>
		<pubDate>Sat, 11 Dec 2010 06:08:36 +0000</pubDate>
		<guid isPermaLink="false">#comment-85202</guid>
		<description><![CDATA[I&#039;m running into the exact same issue and have created the exact same ACL. I&#039;ve scored 470 of a possible 471 points on this assignment and this last point is going to drive me bonkers if I can&#039;t find it! The webserver, located on the inside at 10.0.1.2, is not accessible from the outside. If the FIREWALL ACL has not been created, the public-to-private mapping &quot;ip nat inside source static 10.0.1.2 209.165.200.246&quot; works fine. The moment the ACL is created, you get &quot;Request Timeout&quot; from the PC located on the outside. The Packet Tracer program&#039;s scoring table is indicating an error with the FIREWALL ACL, but of course doesn&#039;t specify where in the ACL the error is occurring. I don&#039;t have a solution, just wanted to toss my hat in there as someone who is having the same problem :)]]></description>
		<content:encoded><![CDATA[<p>I&#8217;m running into the exact same issue and have created the exact same ACL. I&#8217;ve scored 470 of a possible 471 points on this assignment and this last point is going to drive me bonkers if I can&#8217;t find it! The webserver, located on the inside at 10.0.1.2, is not accessible from the outside. If the FIREWALL ACL has not been created, the public-to-private mapping &#8220;ip nat inside source static 10.0.1.2 209.165.200.246&#8243; works fine. The moment the ACL is created, you get &#8220;Request Timeout&#8221; from the PC located on the outside. The Packet Tracer program&#8217;s scoring table is indicating an error with the FIREWALL ACL, but of course doesn&#8217;t specify where in the ACL the error is occurring. I don&#8217;t have a solution, just wanted to toss my hat in there as someone who is having the same problem <img src='http://itknowledgeexchange.techtarget.com/itanswers/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ifoy</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/extended-acl/#comment-81839</link>
		<dc:creator>ifoy</dc:creator>
		<pubDate>Sat, 25 Sep 2010 15:44:33 +0000</pubDate>
		<guid isPermaLink="false">#comment-81839</guid>
		<description><![CDATA[Any help would be appreciated.]]></description>
		<content:encoded><![CDATA[<p>Any help would be appreciated.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ifoy</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/extended-acl/#comment-81676</link>
		<dc:creator>ifoy</dc:creator>
		<pubDate>Tue, 21 Sep 2010 00:35:38 +0000</pubDate>
		<guid isPermaLink="false">#comment-81676</guid>
		<description><![CDATA[interface FastEthernet0/0
 ip address 10.0.1.1 255.255.255.0
 ip nat inside
 duplex auto
 speed auto

interface Serial0/1/0
 ip address 209.165.201.1 255.255.255.252
 encapsulation ppp
 ppp authentication chap
 ip access-group FIREWALL in
 ip nat outside

ip nat pool XYZCORP 209.165.200.241 209.165.200.245 netmask 255.255.255.248
ip nat inside source list NAT_LIST pool XYZCORP
ip nat inside source static 10.0.1.2 209.165.200.246 
ip classless
ip route 0.0.0.0 0.0.0.0 Serial0/1/0 
ip route 10.4.5.0 255.255.255.0 Serial0/0/1 


ip access-list standard NAT_LIST
    permit 10.0.0.0 0.255.255.255

ip access-list extended FIREWALL
    permit tcp any host 209.165.200.246 eq www
    permit tcp any any established
    permit icmp any any echo-reply
    deny ip any any

Fa0/0 is towards www.xyzcorp.com server.  S0/1/0 is towards the ISP.  I attempted to copy/paste a simulated network diagram, but unsuccessful.]]></description>
		<content:encoded><![CDATA[<p>interface FastEthernet0/0<br />
 ip address 10.0.1.1 255.255.255.0<br />
 ip nat inside<br />
 duplex auto<br />
 speed auto</p>
<p>interface Serial0/1/0<br />
 ip address 209.165.201.1 255.255.255.252<br />
 encapsulation ppp<br />
 ppp authentication chap<br />
 ip access-group FIREWALL in<br />
 ip nat outside</p>
<p>ip nat pool XYZCORP 209.165.200.241 209.165.200.245 netmask 255.255.255.248<br />
ip nat inside source list NAT_LIST pool XYZCORP<br />
ip nat inside source static 10.0.1.2 209.165.200.246<br />
ip classless<br />
ip route 0.0.0.0 0.0.0.0 Serial0/1/0<br />
ip route 10.4.5.0 255.255.255.0 Serial0/0/1 </p>
<p>ip access-list standard NAT_LIST<br />
    permit 10.0.0.0 0.255.255.255</p>
<p>ip access-list extended FIREWALL<br />
    permit tcp any host 209.165.200.246 eq www<br />
    permit tcp any any established<br />
    permit icmp any any echo-reply<br />
    deny ip any any</p>
<p>Fa0/0 is towards <a href="http://www.xyzcorp.com" rel="nofollow">http://www.xyzcorp.com</a> server.  S0/1/0 is towards the ISP.  I attempted to copy/paste a simulated network diagram, but unsuccessful.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: mattmather</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/extended-acl/#comment-81674</link>
		<dc:creator>mattmather</dc:creator>
		<pubDate>Mon, 20 Sep 2010 23:34:00 +0000</pubDate>
		<guid isPermaLink="false">#comment-81674</guid>
		<description><![CDATA[Perhaps post the relevant parts of the config, obviously removing the sensitive stuff ;)]]></description>
		<content:encoded><![CDATA[<p>Perhaps post the relevant parts of the config, obviously removing the sensitive stuff <img src='http://itknowledgeexchange.techtarget.com/itanswers/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: mattmather</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/extended-acl/#comment-81673</link>
		<dc:creator>mattmather</dc:creator>
		<pubDate>Mon, 20 Sep 2010 23:33:19 +0000</pubDate>
		<guid isPermaLink="false">#comment-81673</guid>
		<description><![CDATA[Do you have NAT on the router as well?]]></description>
		<content:encoded><![CDATA[<p>Do you have NAT on the router as well?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ifoy</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/extended-acl/#comment-81657</link>
		<dc:creator>ifoy</dc:creator>
		<pubDate>Mon, 20 Sep 2010 17:05:14 +0000</pubDate>
		<guid isPermaLink="false">#comment-81657</guid>
		<description><![CDATA[I applied the the access-group on the router ( between the router and ISP), in this case, S0/1/0.  Router statement: ip access-group FIREWALL (ACL name) in

Thanks for replying.]]></description>
		<content:encoded><![CDATA[<p>I applied the the access-group on the router ( between the router and ISP), in this case, S0/1/0.  Router statement: ip access-group FIREWALL (ACL name) in</p>
<p>Thanks for replying.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using memcached
Database Caching 6/8 queries in 0.013 seconds using memcached
Object Caching 375/376 objects using memcached

Served from: itknowledgeexchange.techtarget.com @ 2013-05-19 11:42:41 -->