Access Lists

Reviews
Shared by: sparrowjacc
Stats
views:
4
rating:
not rated
reviews:
0
posted:
8/1/2009
language:
English
pages:
0
Access Control Lists Types   Standard Extended Standard ACLs   Use only the packet’s source address for comparison 1-99 Extended ACLs  Provide more precise (finer tuned) packet selection based on:    Source and destination addresses Protocols Port numbers  100-199 Steps to Create an ACL    Create ACL in global config Assign to interface Decide the direction   In Out How do ACLs work?    Processing occurs line by line from top to bottom. New lines are added at the end of the current list. Last line of an ACL is an implicit “deny any.” How does a Standard ACL work?  If source IP address is matched:  Permit or deny statement is processed    Permit – action in ACL is performed Deny – packet is dropped Implicit Deny – If a packet’s address does not match an earlier statement an implicit deny any occurs at the end of every ACL and the packet is dropped. Wildcard Masks    Are used to specify (by bits) the traffic you are trying to filter by address. Use 1s to ignore, 0s to match. In the example below, only the 1st 2 octets will be examined:  172.16.0.0 0.0.255.255 Global Standard ACL command   access-list access-list-number {permit |deny} source-ip-address wildcard-mask [log] Log – causes each packet that matches this statement to generate a log entry that is recorded by the router. Examples of Standard ACLs  To permit all packets for the network number 172.16.0.0  Access-list 20 permit 172.16.0.0 0.0.255.255 Examples Cont’d  To permit traffic from the host 172.16.1.1 only  Access-list 20 permit 172.16.1.1 0.0.0.0 Examples Cont’d  To permit traffic from any source address.  Access-list 20 permit 0.0.0.0 255.255.255.255 OR  Access-list 20 permit any Examples Cont’d  To permit traffic from the subnet 12.16.0.0 through 12.31.0.0  Access-list 20 permit 12.16.0.0 0.15.255.255 Identical Statements   Access-list 22 permit 0.0.0.0 255.255.255.255 Access-list 22 permit any Identical Statements   Access-list 23 permit 172.16.1.1 0.0.0.0 Access-list 23 permit host 172.16.1.1 How does an Extended ACL work?   All conditions must match Test sequence in this order      Source Address Destination Address Protocol Port No. or Protocol Options Permit or Deny decision Extended ACL command  access-list number {permit|deny} protocol source-ip-address sourcewildcard-mask destination-ip-address destination-wildcard-mask eq portnumber [log] Some Protocols with Port Numbers         FTP – 21 Telnet – 23 SMTP – 25 DNS – 53 TFTP – 69 WWW, HTML – 80 POP3 - 110 SNMP - 161 Major differences  Standard ACL   Use only source address and requires fewer CPU cycles. Place as close to destination as possible. More flexible and requires more CPU cycles. Place as close to source as possible. (This keeps undesired traffic and ICMP messages away from the network backbone.)  Extended ACL   Do I place an ACL in?  In   Requires less CPU processing because every packet bypasses processing before it is routed. Filtering decision is made prior to the routing table. Do I place an ACL out?  Out   Routing decision has been made and the packet is switched to the proper outbound interface before it is tested against the access list. ACLs are outbound unless otherwise specified.

Related docs
IP Access Lists com
Views: 56  |  Downloads: 2
ACCESS LISTS
Views: 1  |  Downloads: 0
Access Control Lists
Views: 3  |  Downloads: 0
Router Access Lists
Views: 63  |  Downloads: 7
Lab18 for Packet Tracer (Access Control Lists)
Views: 37  |  Downloads: 1
Lab17 for Packet Tracer (Access Control Lists)
Views: 36  |  Downloads: 0
Access Control Lists (ACLs)
Views: 7  |  Downloads: 3
lists of browsers
Views: 10  |  Downloads: 3
selecting companies and lists
Views: 0  |  Downloads: 0
Configuring Access Control Lists
Views: 1  |  Downloads: 0
Other docs by sparrowjacc
Shareholders Resolution Approving Sale of Stock
Views: 259  |  Downloads: 4
Minutes of First Directors Meeting
Views: 295  |  Downloads: 10
Drugstorecom Inc Ammendments and By laws
Views: 280  |  Downloads: 1
Equipment lease checklist
Views: 395  |  Downloads: 8
Board Resolution Filling Vacancy on Board
Views: 201  |  Downloads: 4
Checklist for purchasing used vehicles
Views: 355  |  Downloads: 9
Demand For Payment
Views: 254  |  Downloads: 6
Employee Appraisal Form
Views: 1720  |  Downloads: 51
Standard Form 26 Award or Contract
Views: 407  |  Downloads: 2
DEMAND FOR PAYMENT
Views: 379  |  Downloads: 11