09.12.2012 Views

Understanding the network.pdf - Back to Home

Understanding the network.pdf - Back to Home

Understanding the network.pdf - Back to Home

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

trace Multicast trace IGMP<br />

log Log matches against this entry All<br />

pro<strong>to</strong>cols<br />

IP<br />

log-input Log matches against this entry, including input All IP<br />

interface<br />

pro<strong>to</strong>cols<br />

precedence Match packets with given precedence value All<br />

pro<strong>to</strong>cols<br />

IP<br />

<strong>to</strong>s Match packets with given TOS value All<br />

pro<strong>to</strong>cols<br />

IP<br />

Match availability depends on <strong>the</strong> kind of pro<strong>to</strong>col being used <strong>to</strong> create an ACL entry.<br />

In <strong>the</strong> case of TCP and UDP, <strong>the</strong>re are varieties of matches that can be used,<br />

whereas routing and tunneling pro<strong>to</strong>cols are quite limited. TCP and UDP use<br />

transport layer service port numbers for port-value matching. For example, let's<br />

create a traffic filter ACL that permits inbound SMTP mail delivery and DNS service:<br />

asbr-a2(config)#access-list 102 permit tcp any any eq 25<br />

asbr-a2(config)#access-list 102 permit tcp any any eq 53<br />

asbr-a2(config)#access-list 102 permit udp any any gt 1024<br />

asbr-a2(config)#access-list 102 permit tcp any any gt 1024<br />

asbr-a2(config)#interface s0<br />

asbr-a2(config-if)# ip access-group 102 in<br />

By using <strong>the</strong> opera<strong>to</strong>r/port-value pair, only inbound mail and DNS zone transfers<br />

are permitted. The gt 1024 statements permit <strong>the</strong> local users <strong>to</strong> access external<br />

Internet hosts. Table 9.4 provides a list of commonly filtered TCP and UDP service<br />

ports.<br />

Table 9.4. Common Internet Known Service Ports<br />

Service ID Service Name Transport Layer Pro<strong>to</strong>col and Port<br />

Number<br />

Bgp Border Gateway Pro<strong>to</strong>col TCP 179<br />

Bootp/dhcp Dynamic Host Configuration UDP 67<br />

Pro<strong>to</strong>col<br />

Cmd UNIX R commands TCP 514<br />

Domain Domain Name Service TCP and UDP 53

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!