我试图限制对我们的 SIP 服务器的访问,209.85.2.10但是,我对permit ip any any log. 它不会允许所有东西进入吗?没有它,我失去了所有其他所需的流量。
问题,如何将访问限制5060为仅访问permit ip any any log并保留其余流量(即 http、smtp ..)。
这permit ip any any log似乎与允许其他服务器连接的约束相矛盾。
内部网络
interface GigabitEthernet0/1
ip address 192.168.2.1 255.255.255.0
ip nat inside
ip access-group 104 out
exit
ip access-list extended 104
permit udp host 209.85.2.10 host 192.168.2.5 eq 5060 log
permit ip any any log
deny ip any any log
deny tcp any any log
deny udp any any log
exit
更新
所以我需要将上面的更改为
ip access-list extended 104
permit udp host 209.85.2.10 host 192.168.2.5 eq 5060 log
deny ip any host 192.168.2.5 log
permit ip any any log
exit
那么这会按预期工作吗?
i)仅接受来自 from 的5060访问,并拒绝端口上的其余尝试ii) 让其他流量从网络中的任何地方进入任何地方,但是?192.168.2.5209.85.2.1050605060
更新最终产品
对于那些将来会找到这篇文章的人。由于此线程中两位先生的帮助,这是对我有用的配置。
ip access-list extended 104
permit tcp any host 192.168.2.5 eq 53
permit udp any host 192.168.2.5 eq 53
permit tcp any host 192.168.2.10 eq 25
permit tcp any host 192.168.2.10 eq 587
permit tcp any host 192.168.2.10 eq 993
permit tcp any host 192.168.2.10 eq 995
permit tcp any host 192.168.2.15 eq 80
permit tcp any host 192.168.2.15 eq 443
permit udp host 205.205.22.186 host 192.168.2.5 eq 5060
permit udp host 205.205.74.186 host 192.168.2.5 eq 5060
permit udp host 70.83.45.11 host 192.168.2.5 eq 5060
permit udp any host 192.168.2.20 eq 5080
permit udp any host 192.168.2.5 range 8000 65535
permit tcp any eq 25 host 192.168.2.10 range 1024 65535 established
permit tcp any eq 53 host 192.168.2.5 range 1024 65535 established
permit tcp any eq 53 host 192.168.2.10 range 1024 65535 established
permit tcp any eq 53 host 192.168.2.15 range 1024 65535 established
permit tcp any eq 53 host 192.168.2.20 range 1024 65535 established
permit udp any eq 53 host 192.168.2.5 range 1024 65535
permit udp any eq 53 host 192.168.2.10 range 1024 65535
permit udp any eq 53 host 192.168.2.15 range 1024 65535
permit udp any eq 53 host 192.168.2.20 range 1024 65535
permit tcp any eq 80 host 192.168.2.5 range 1024 65535 established
permit tcp any eq 80 host 192.168.2.10 range 1024 65535 established
permit tcp any eq 80 host 192.168.2.15 range 1024 65535 established
permit tcp any eq 80 host 192.168.2.20 range 1024 65535 established
deny ip any host 192.168.2.5 log
deny ip any host 192.168.2.10 log
deny ip any host 192.168.2.15 log
deny ip any host 192.168.2.20 log
permit ip any any
exit
ip nat inside source static 192.168.2.5 77.77.77.77 route-map voip-rtp extendable
提前致谢,
缺口。