Word :    Username :           
 

Situation:
I want to block certain internal IP addresses from on my internal network from reaching the external network.
The router is using network adress translation from the internal network to the external network.

Initial Solution:
I set up an outgoing access list on external interface to block the IP addresses.

Problem:
The addresses are apparently translated before they reach the interface. My logs only show the external address going through. The access-list isn't touching anything going through it.

Question:
How do I apply an outgoing access list to the interface while NAT is running?

Pain is the realization of your own weakness.

Sponsored Links
Register or log in to remove.

just put an access list on the internal interface. i dont see your problem.

wpdclan.com cs game server - 69.12.5.119:27015

Reply to jihiggs

Already tried that, it didn't quite work the way I expected.
There are a lot of details that I'd rather not waste my time typing.
Let's just say that's not a option.

Pain is the realization of your own weakness.

Reply to Bahumut

can you do it with the mac address on the switches?

wpdclan.com cs game server - 69.12.5.119:27015

Reply to jihiggs

Don't have access to the switches.

I got it figured out though.
I can permit outgoing requests on the router by MAC address.

Thanks for the help jihiggs.

Pain is the realization of your own weakness.

Reply to Bahumut
Tom's Hardware > Forum > General Networking > General Gateways, Routers and Firewalls > Access-list with Nat
Go to:

There are 1071 identified and unidentified users. To see the list of identified users, Click here.

Please mind

You are about to answer a thread that has been inactive for more than 6 months.
If you still wish to proceed, please ensure that your posting is original and does not duplicate or overlap any prior responses to this thread.

Add a reply Cancel
Sponsored links
  • Ask the community now
  • Publish
Ad
They won a badge
Join us in greeting them