Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

Recommended Posts

Posted (edited)

We've recently had CCTV installed and added them into VLAN 30.

 

I created an ACL but it isn't allowing me to connect to the DVR on port 81. I can ping the devices and the devices do automatically obtain IP addresses etc. My ACL is below...

 

AD/DHCP/DNS is 10.0.10.2 and 10.0.10.3

 

CCTV NVR is 10.0.30.2

ip access-list extended "CCTV"

1 remark "Allow devices in VLAN 50 to reply to pings initiated from devices outside their VLAN"

2 permit icmp 10.0.30.0 0.0.0.255 0.0.0.0 255.255.255.255 0

10 remark "Allow DHCP traffic"

11 permit udp 10.0.30.0 0.0.0.255 eq 68 10.0.10.2 0.0.0.0 eq 67

12 permit udp 10.0.30.0 0.0.0.255 eq 68 10.0.10.3 0.0.0.0 eq 67

13 remark "Allow DNS traffic"

14 permit tcp 10.0.30.0 0.0.0.255 10.0.10.2 0.0.0.0 eq 53

15 permit udp 10.0.30.0 0.0.0.255 10.0.10.2 0.0.0.0 eq 53

16 permit tcp 10.0.30.0 0.0.0.255 10.0.10.3 0.0.0.0 eq 53

17 permit udp 10.0.30.0 0.0.0.255 10.0.10.3 0.0.0.0 eq 53

20 remark "Deny any client using SSH"

21 deny tcp 10.0.30.0 0.0.0.255 0.0.0.0 255.255.255.255 eq 22

22 remark "Deny any client using Telnet"

23 deny tcp 10.0.30.0 0.0.0.255 0.0.0.0 255.255.255.255 eq 23

30 remark "Deny any client using HTTP(S) to gain access to any Switch configuration"

31 deny tcp 10.0.30.0 0.0.0.255 10.0.5.0 0.0.0.255 eq 80

32 deny tcp 10.0.30.0 0.0.0.255 10.0.5.0 0.0.0.255 eq 443

40 remark "Deny access to other VLANS"

41 deny ip 10.0.30.0 0.0.0.255 10.0.10.0 0.0.0.255

42 deny ip 10.0.30.0 0.0.0.255 10.0.20.0 0.0.1.255

50 remark "Deny all other traffic (for more security)"

51 deny ip 0.0.0.0 255.255.255.255 0.0.0.0 255.255.255.255

exit

 

Access via browser is http://10.0.30.2:81

 

If I remove the ACL from the VLAN it works. If I add the ACL into the VLAN and try accessing the NVR it doesn't work.

Edited by Chuckster
Posted

Just an update...

 

I addede after line 32 the following

 

35 remark "Allow bidirectional traffic that is initiated from other VLANS"

36 permit ip 10.0.30.0 0.0.0.255 0.0.0.0 255.255.255.255

 

All workings fine now.

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...