Implicit deny at the end of the ACL...You didn't specifically permit telnet access so it is denied.

chloe K wrote:
Hi I am doing the following access-list for www to restrict to switch http access
  but when I apply it in the interface, i suddenly lost telnet connection.
  Why?
Extended IP access list 110
    permit tcp 192.168.0.0 0.255.255.255 any eq www
    permit tcp 172.16.0.0 0.255.255.255 any eq www
    permit tcp 10.0.0.0 0.255.255.255 any eq www
    deny tcp any eq www any
    deny tcp any eq www any log
switch(config)#interface VLAN1
  switch(config-if)#ip access-group 110 in
switch(config-if)#


---------------------------------
Now with a new friend-happy design! Try the new Yahoo! Canada Messenger
_______________________________________________
cisco-nsp mailing list  [email protected]
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/

_______________________________________________
cisco-nsp mailing list  [email protected]
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/

Reply via email to