Cisco 4700M Configuration Manual page 64

Application control engine appliance security
Hide thumbs Also See for 4700M:
Table of Contents

Advertisement

ACL Configuration Examples
If you want to allow an outside host to access an inside host, you can apply an
inbound ACL to the outside interface. You must specify the translated address of
the inside host in the ACL because that address is the address that can be used on
the outside network (see
Figure 1-4
Permit from
The following commands create an ACL that allows outside host 209.165.200.225
to access inside host 209.165.201.5 (the translated address of the host 10.1.1.34).
The last command applies the ACL to VLAN interface 100.
host1/Admin(config)# access-list OUTSIDE extended permit ip host
209.165.200.225 host 209.165.201.5
host1/Admin(config)# interface vlan 100
host1/Admin(config-if)# access-group input OUTSIDE
Cisco 4700 Series Application Control Engine Appliance Security Configuration Guide
1-40
Figure
1-4).
IP Addresses in ACLs: NAT used for Destination Addresses
209.165.200.225
ACL
209.165.200.225
to
209.165.201.5
Outside
ACE
Inside
10.1.1.34
Static NAT
Chapter 1
Configuring Security Access Control Lists
209.165.201.5
OL-16202-01

Advertisement

Table of Contents
loading

This manual is also suitable for:

4700 series

Table of Contents