09-19-2019 06:39 AM
create access-list santral-pbx-010 " source-address 10.242.2.0/24 ; destination-address 10.150.101.0/24 ;" " permit ;" application "Cli"
create access-list santral-pbx-020 " source-address 192.168.10.0/24 ; destination-address 10.150.101.0/24 ;" " permit ;" application "Cli"
create access-list santral-pbx-030 " source-address 192.168.1.44/32 ; destination-address 10.150.101.0/24 ;" " permit ;" application "Cli"
create access-list santral-pbx-040 " source-address 192.168.1.183/32 ; destination-address 10.150.101.0/24 ;" " permit ;" application "Cli"
create access-list santral-pbx-050 " source-address 10.50.0.0/24 ; destination-address 10.150.101.0/24 ;" " permit ;" application "Cli"
create access-list santral-pbx-060 " source-address 10.110.101.0/24 ; destination-address 10.150.101.0/24 ;" " permit ;" application "Cli"
create access-list santral-pbx-070 " source-address 10.120.101.0/24 ; destination-address 10.150.101.0/24 ;" " permit ;" application "Cli"
create access-list santral-pbx-080 " source-address 10.130.101.0/24 ; destination-address 10.150.101.0/24 ;" " permit ;" application "Cli"
create access-list santral-pbx-090 " source-address 10.141.26.0/24 ; destination-address 10.150.101.0/24 ;" " permit ;" application "Cli"
create access-list santral-pbx-100 " source-address 10.146.101.0/24 ; destination-address 10.150.101.0/24 ;" " permit ;" application "Cli"
create access-list santral-pbx-110 " source-address 10.150.101.0/24 ; destination-address 10.150.101.0/24 ;" " permit ;" application "Cli"
create access-list santral-pbx-120 " source-address 10.160.101.0/24 ; destination-address 10.150.101.0/24 ;" " permit ;" application "Cli"
create access-list santral-pbx-130 " source-address 10.111.101.0/24 ; destination-address 10.150.101.0/24 ;" " permit ;" application "Cli"
create access-list santral-pbx-deny " source-address 0.0.0.0/0 ; destination-address 10.150.101.0/24 ;" " deny ;" application "Cli"
configure access-list add santral-pbx-010 last priority 0 zone SYSTEM vlan Santral-PBX ingress
configure access-list add santral-pbx-020 last priority 0 zone SYSTEM vlan Santral-PBX ingress
configure access-list add santral-pbx-030 last priority 0 zone SYSTEM vlan Santral-PBX ingress
configure access-list add santral-pbx-040 last priority 0 zone SYSTEM vlan Santral-PBX ingress
configure access-list add santral-pbx-050 last priority 0 zone SYSTEM vlan Santral-PBX ingress
configure access-list add santral-pbx-060 last priority 0 zone SYSTEM vlan Santral-PBX ingress
configure access-list add santral-pbx-070 last priority 0 zone SYSTEM vlan Santral-PBX ingress
configure access-list add santral-pbx-080 last priority 0 zone SYSTEM vlan Santral-PBX ingress
configure access-list add santral-pbx-090 last priority 0 zone SYSTEM vlan Santral-PBX ingress
configure access-list add santral-pbx-100 last priority 0 zone SYSTEM vlan Santral-PBX ingress
configure access-list add santral-pbx-110 last priority 0 zone SYSTEM vlan Santral-PBX ingress
configure access-list add santral-pbx-120 last priority 0 zone SYSTEM vlan Santral-PBX ingress
configure access-list add santral-pbx-130 last priority 0 zone SYSTEM vlan Santral-PBX ingress
configure access-list add santral-pbx-deny last priority 0 zone SYSTEM vlan Santral-PBX ingress
Solved! Go to Solution.
09-25-2019 03:35 PM
09-26-2019 05:45 AM
09-25-2019 03:35 PM
09-25-2019 12:06 PM
entry santralpbx-allowed-networks-01 {
if match all {
source-address 10.242.2.0/24;
destination-address 10.150.101.0/24;
} then {
permit;
count santralpbx-permit-count;
}
}
entry santralpbx-allowed-networks-02 {
if match all {
source-address 192.168.10.0/24;
destination-address 10.150.101.0/24;
} then {
permit;
count santralpbx-permit-count;
}
}
entry santralpbx-allowed-networks-03 {
if match all {
source-address 192.168.1.44/32;
destination-address 10.150.101.0/24;
} then {
permit;
count santralpbx-permit-count;
}
}
entry santralpbx-allowed-networks-04 {
if match all {
source-address 192.168.1.183/32;
destination-address 10.150.101.0/24;
} then {
permit;
count santralpbx-permit-count;
}
}
entry santralpbx-allowed-networks-05 {
if match all {
source-address 10.50.0.0/24;
destination-address 10.150.101.0/24;
} then {
permit;
count santralpbx-permit-count;
}
}
entry santralpbx-allowed-networks-06 {
if match all {
source-address 10.110.101.0/24;
destination-address 10.150.101.0/24;
} then {
permit;
count santralpbx-permit-count;
}
}
entry santralpbx-allowed-networks-07 {
if match all {
source-address 10.120.101.0/24;
destination-address 10.150.101.0/24;
} then {
permit;
count santralpbx-permit-count;
}
}
entry santralpbx-allowed-networks-08 {
if match all {
source-address 10.130.101.0/24;
destination-address 10.150.101.0/24;
} then {
permit;
count santralpbx-permit-count;
}
}
entry santralpbx-allowed-networks-09 {
if match all {
source-address 10.141.26.0/24;
destination-address 10.150.101.0/24;
} then {
permit;
count santralpbx-permit-count;
}
}
entry santralpbx-allowed-networks-10 {
if match all {
source-address 10.146.101.0/24;
destination-address 10.150.101.0/24;
} then {
permit;
count santralpbx-permit-count;
}
}
entry santralpbx-allowed-networks-11 {
if match all {
source-address 10.150.101.0/24;
destination-address 10.150.101.0/24;
} then {
permit;
count santralpbx-permit-count;
}
}
entry santralpbx-allowed-networks-12 {
if match all {
source-address 10.160.101.0/24;
destination-address 10.150.101.0/24;
} then {
permit;
count santralpbx-permit-count;
}
}
entry santralpbx-allowed-networks-13 {
if match all {
source-address 10.111.101.0/24;
destination-address 10.150.101.0/24;
} then {
permit;
count santralpbx-permit-count;
}
}
entry santralpbx-deny-all {
if {
source-address 0.0.0.0/0;
destination-address 10.150.101.0/24;
} then {
deny;
count santralpbx-deny-count;
}
}
configure access-list santral-pbx vlan "Santral-PBX" ingress
SAVSAT-METRO.3 # show access-list counter ingress
Policy Name Vlan Name Port Direction
Counter Name Packet Count Byte Count
==================================================================
santral-pbx Santral-PBX * ingress
santralpbx-deny-count 0
santralpbx-permit-count 11431