19.07.2013 Views

CCNA Complete Guide 2nd Edition.pdf - Cisco Learning Home

CCNA Complete Guide 2nd Edition.pdf - Cisco Learning Home

CCNA Complete Guide 2nd Edition.pdf - Cisco Learning Home

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 19<br />

IP Access Control Lists<br />

- Access control list (ACL) is an effective and important network security feature. With the ability<br />

to classify inbound and outbound packets going through the router or switch interfaces, Access<br />

lists are able to define rules that allow or deny certain type of packets flowing through a network.<br />

Ex: Employees in Department A, Building A are not allowed to access Server B in Building B;<br />

Everyone is denied the access to Server C except Department B.<br />

- ACLs are categorized as Standard (simpler logic) and Extended (more complex logic) ACLs.<br />

- ACLs can permit and deny packets based on L3 (IP address) and L4 (port number) information.<br />

Standard IP Access Lists<br />

1<br />

172.16.1.2<br />

Access denied<br />

to ServerA<br />

2<br />

172.16.2.2<br />

3 4<br />

172.16.2.3 172.16.2.4<br />

Figure 19-1: Network Setup for Access Control List<br />

- Figure 19-1 shows a sample scenario that demonstrates the usage of ACLs – deny the access of<br />

PC2 to ServerA. It shows the packet flow for PC2 to access ServerA would typically go through<br />

a switch, RT2, RT3, another switch, and finally ServerA. In order to block the packets sent by<br />

PC2 to arrive at ServerA, the best place to apply ACL filtering logic would be on RT2 or RT3.<br />

Figure 19-2 shows the internal processing in RT3 when a packet enters it through S0/1 and exits<br />

through Fa1/0.<br />

Inbound<br />

ACL<br />

Fa1/0<br />

Fa1/0<br />

Figure 19-2: Internal Processing in RT3<br />

135<br />

RT1<br />

S0/0<br />

RT2<br />

S0/0<br />

Routing<br />

Logic<br />

S0/1<br />

S0/0<br />

S0/1<br />

RT3<br />

S0/1<br />

Fa1/0<br />

Outbound<br />

ACL<br />

ServerA<br />

172.16.3.2<br />

S0/1 Permit<br />

Permit Fa1/0<br />

Deny<br />

Discard<br />

Deny<br />

Copyright © 2008 Yap Chin Hoong<br />

yapchinhoong@hotmail.com

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!