09.12.2012 Views

Understanding the network.pdf - Back to Home

Understanding the network.pdf - Back to Home

Understanding the network.pdf - Back to Home

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Table 9.5. AppleTalk ACL<br />

Filtering Matches<br />

ACL Match Opera<strong>to</strong>r Data Value Description<br />

1-65279 Match on a AppleTalk node address<br />

<strong>network</strong> Match on a Phase 1 AppleTalk <strong>network</strong><br />

address<br />

includes Match on a Phase 2 AppleTalk <strong>network</strong><br />

address<br />

nbp Match on a name binding pro<strong>to</strong>col<br />

within<br />

(object, type, zone)<br />

Match on a Phase 2 AppleTalk <strong>network</strong><br />

address<br />

zone Match on a AppleTalk zone name<br />

AppleTalk ACLs are created with <strong>the</strong> same line-by-line entry format used <strong>to</strong> create<br />

IP ACLs, and you should follow <strong>the</strong> same approach for ACL creation, editing, and<br />

installation—in o<strong>the</strong>r words, using a text edi<strong>to</strong>r. The global configuration command<br />

for creating AppleTalk ACL action statements is . Aside from care and<br />

feeding, however, AppleTalk ACLs are very different from <strong>the</strong>ir IP and IPX<br />

counterparts, particularly when it comes <strong>to</strong> filtering AppleTalk's named space.<br />

In Chapter 3, "The Networker's Guide <strong>to</strong> AppleTalk, IPX, and NetBIOS," we reviewed<br />

AppleTalk's naming entities. The NBP provides <strong>the</strong> mechanisms needed <strong>to</strong> map and<br />

distribute object:name@zone information throughout <strong>the</strong> <strong>network</strong>. ZIP is used for<br />

<strong>the</strong> creation and distribution of zone information between routers and nodes, both<br />

of which compile <strong>the</strong>ir own Zone Information Tables (ZITs). To filter <strong>the</strong>se services,<br />

two different ACLs are required. NBP and <strong>network</strong> filtering (which conceptually<br />

resembles IP source/destination filtering) are applied <strong>to</strong> an interface as an inbound<br />

or outbound command. Both NBP object:type@zone<br />

filtering and AppleTalk <strong>network</strong> address filtering are applied with <strong>the</strong> command. It is also possible for both types of filtering <strong>to</strong> be<br />

performed on <strong>the</strong> same list.<br />

Because zone information distribution filtering is accomplished through two<br />

different operations, it also uses two different filter applications. The<br />

is used <strong>to</strong> suppress zone information from being sent <strong>to</strong><br />

user workstations when ZIP requests are made. When <strong>the</strong> <br />

is in place, only <strong>the</strong> zones permitted in <strong>the</strong> ACL will be sent in <strong>the</strong> ZIP response. To

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!